Show filters
12 Total Results
Displaying 1-10 of 12
Sort by:
Attacker Value
Unknown

CVE-2024-12057

Disclosure Date: December 09, 2024 (last updated December 21, 2024)
User credentials (login & password) are inserted into log files when a user tries to authenticate using a version of a Web client that is not compatible with that of the PcVue Web back end. By exploiting this vulnerability, an attacker could retrieve the credentials of a user by accessing the Log File. Successful exploitation of this vulnerability could lead to unauthorized access to the application.
0
Attacker Value
Unknown

CVE-2024-12056

Disclosure Date: December 04, 2024 (last updated December 21, 2024)
The Client secret is not checked when using the OAuth Password grant type. By exploiting this vulnerability, an attacker could connect to a web server using a client application not explicitly authorized as part of the OAuth deployment. Exploitation requires valid credentials and does not permit the attacker to bypass user privileges.
0
Attacker Value
Unknown

CVE-2022-4312

Disclosure Date: December 12, 2022 (last updated November 08, 2023)
A cleartext storage of sensitive information vulnerability exists in PcVue versions 8.10 through 15.2.3. This could allow an unauthorized user with access the email and short messaging service (SMS) accounts configuration files to discover the associated simple mail transfer protocol (SMTP) account credentials and the SIM card PIN code. Successful exploitation of this vulnerability could allow an unauthorized user access to the underlying email account and SIM card.
Attacker Value
Unknown

CVE-2022-4311

Disclosure Date: December 12, 2022 (last updated November 08, 2023)
An insertion of sensitive information into log file vulnerability exists in PcVue versions 15 through 15.2.2. This could allow a user with access to the log files to discover connection strings of data sources configured for the DbConnect, which could include credentials. Successful exploitation of this vulnerability could allow other users unauthorized access to the underlying data sources.
Attacker Value
Unknown

CVE-2022-2569

Disclosure Date: August 23, 2022 (last updated October 08, 2023)
The affected device stores sensitive information in cleartext, which may allow an authenticated user to access session data stored in the OAuth database belonging to legitimate users
Attacker Value
Unknown

CVE-2020-26869

Disclosure Date: October 12, 2020 (last updated February 22, 2025)
ARC Informatique PcVue prior to version 12.0.17 is vulnerable to information exposure, allowing unauthorized users to access session data of legitimate users. This issue also affects third-party systems based on the Web Services Toolkit.
Attacker Value
Unknown

CVE-2020-26868

Disclosure Date: October 12, 2020 (last updated February 22, 2025)
ARC Informatique PcVue prior to version 12.0.17 is vulnerable to a denial-of-service attack due to the ability of an unauthorized user to modify information used to validate messages sent by legitimate web clients. This issue also affects third-party systems based on the Web Services Toolkit.
Attacker Value
Unknown

CVE-2020-26867

Disclosure Date: October 12, 2020 (last updated February 22, 2025)
ARC Informatique PcVue prior to version 12.0.17 is vulnerable due to the deserialization of untrusted data, which may allow an attacker to remotely execute arbitrary code on the web and mobile back-end server.
Attacker Value
Unknown

CVE-2011-4043

Disclosure Date: April 03, 2012 (last updated October 04, 2023)
Integer overflow in an unspecified ActiveX control in SVUIGrd.ocx in ARC Informatique PcVue 6.0 through 10.0, FrontVue, and PlantVue allows remote attackers to execute arbitrary code via a large value for an integer parameter, leading to a buffer overflow.
0
Attacker Value
Unknown

CVE-2011-4042

Disclosure Date: April 03, 2012 (last updated October 04, 2023)
An unspecified ActiveX control in SVUIGrd.ocx in ARC Informatique PcVue 6.0 through 10.0, FrontVue, and PlantVue allows remote attackers to execute arbitrary code by using a crafted HTML document to obtain control of a function pointer.
0