Impact
The flaw is an information disclosure that lets attackers positioned in a man‑in‑the‑middle scenario read sensitive data sent by IQSIGHT BVMS. Credentials, configuration details, or other confidential information could be exposed, undermining confidentiality. The weakness is classified as CWE‑321, indicating insecure key management practices that allow the data to be captured.
Affected Systems
IQSIGHT BVMS versions 4.5 through 12.3 are affected by this disclosure flaw, regardless of operating system or deployment environment.
Risk and Exploitability
The CVSS score of 8.7 marks this vulnerability as high severity. EPSS data is not available and the vulnerability is not listed in CISA’s KEV catalog, suggesting no confirmed exploitation at this time. An attacker can exploit the weakness by intercepting traffic between a client and the BVMS server; weak key handling in the transport layer permits the intercepted data to be read.
OpenCVE Enrichment