Impact
Based on the description, the Genucenter web interface before version 8.0p11 exposes SNMP responses to users assigned the Service or Admin role. This flaw reveals sensitive credential material, allowing those users to decrypt SNMP traffic or impersonate SNMP agents, potentially granting unauthorized access to network devices and enabling compromise of network infrastructure. The weakness is classified as an information disclosure (CWE‑201).
Affected Systems
All genua Genucenter installations running a version earlier than 8.0p11 are affected. The vulnerability applies to the web interface accessed by users assigned the Service or Admin role or configuration differences are specified.
Risk and Exploitability
With a CVSS score of 4.3 the vulnerability is Low severity. The EPSS score is < 1% and it is not listed in the CISA KEV catalog, indicating no known widespread exploitation. Based on the description, it is inferred that exploitation requires valid credentials that grant Service or Admin level access to the web interface, making it an insider or compromised‑credential scenario. The likely attack vector is an authenticated web interface session by a user with Service or Admin privileges, which may lead to unauthorized decryption of of SNMP agents.
OpenCVE Enrichment