Show filters
9 Total Results
Displaying 1-9 of 9
Sort by:
Attacker Value
Unknown
CVE-2024-12057
Disclosure Date: December 09, 2024 (last updated December 21, 2024)
User credentials (login & password) are inserted into log files when a user tries to authenticate using a version of a Web client that is not compatible with that of the PcVue Web back end.
By exploiting this vulnerability, an attacker could retrieve the credentials of a user by accessing the Log File. Successful exploitation of this vulnerability could lead to unauthorized access to the application.
0
Attacker Value
Unknown
CVE-2024-12056
Disclosure Date: December 04, 2024 (last updated December 21, 2024)
The Client secret is not checked when using the OAuth Password grant type.
By exploiting this vulnerability, an attacker could connect to a web server using a client application not explicitly authorized as part of the OAuth deployment.
Exploitation requires valid credentials and does not permit the attacker to bypass user privileges.
0
Attacker Value
Unknown
CVE-2022-4312
Disclosure Date: December 12, 2022 (last updated November 08, 2023)
A cleartext storage of sensitive information vulnerability exists in PcVue versions 8.10 through 15.2.3. This could
allow an unauthorized user with access the email and short messaging service (SMS) accounts configuration files
to discover the associated simple mail transfer protocol (SMTP) account credentials and the SIM card PIN code.
Successful exploitation of this vulnerability could allow an unauthorized user access to the underlying email
account and SIM card.
0
Attacker Value
Unknown
CVE-2022-4311
Disclosure Date: December 12, 2022 (last updated November 08, 2023)
An insertion of sensitive information into log file vulnerability exists in PcVue versions 15 through 15.2.2. This
could allow a user with access to the log files to discover connection strings of data sources configured for the
DbConnect, which could include credentials. Successful exploitation of this vulnerability could allow other users
unauthorized access to the underlying data sources.
0
Attacker Value
Unknown
CVE-2022-2569
Disclosure Date: August 23, 2022 (last updated October 08, 2023)
The affected device stores sensitive information in cleartext, which may allow an authenticated user to access session data stored in the OAuth database belonging to legitimate users
0
Attacker Value
Unknown
CVE-2011-4043
Disclosure Date: April 03, 2012 (last updated October 04, 2023)
Integer overflow in an unspecified ActiveX control in SVUIGrd.ocx in ARC Informatique PcVue 6.0 through 10.0, FrontVue, and PlantVue allows remote attackers to execute arbitrary code via a large value for an integer parameter, leading to a buffer overflow.
0
Attacker Value
Unknown
CVE-2011-4042
Disclosure Date: April 03, 2012 (last updated October 04, 2023)
An unspecified ActiveX control in SVUIGrd.ocx in ARC Informatique PcVue 6.0 through 10.0, FrontVue, and PlantVue allows remote attackers to execute arbitrary code by using a crafted HTML document to obtain control of a function pointer.
0
Attacker Value
Unknown
CVE-2011-4045
Disclosure Date: April 03, 2012 (last updated October 04, 2023)
Buffer overflow in an unspecified ActiveX control in aipgctl.ocx in ARC Informatique PcVue 6.0 through 10.0, FrontVue, and PlantVue allows remote attackers to cause a denial of service via a crafted HTML document.
0
Attacker Value
Unknown
CVE-2011-4044
Disclosure Date: April 03, 2012 (last updated October 04, 2023)
An unspecified ActiveX control in SVUIGrd.ocx in ARC Informatique PcVue 6.0 through 10.0, FrontVue, and PlantVue allows remote attackers to modify files via calls to unknown methods.
0