Impact
When OpenSSL is unavailable the TYPO3 SYSSY extension transmits system information in cleartext instead of encrypting it. The flaw allows an attacker who already controls the SYSSY API key to read sensitive system data. This vulnerability is a classic example of cleartext transmission of sensitive information, as catalogued by CWE‑319, and can result in a breach of confidentiality for the affected TYPO3 installation.
Affected Systems
The vulnerability affects the TYPO3 extension "SYSSY - TYPO3 Monitoring & Security Checks". No specific version numbers are provided, so any installation of this extension on a TYPO3 site that has the extension present is potentially exposed, regardless of TYPO3 core version.
Risk and Exploitability
The CVSS score of 5.3 places this flaw in the medium severity range. EPSS is not available and the vulnerability is not listed in the CISA KEV catalog, indicating no evidence of widespread exploitation at present. Exploitation requires the attacker to possess the SYSSY API key, implying that the threat surface is limited to environments where such a key has already been compromised or leaked. Consequently the overall risk is moderate but can be elevated if the API key is not adequately protected.
OpenCVE Enrichment