CVE-2022-3217

Publication date

2022-09-16 20:15:34

Family

tenable

State

PUBLISHED

Description

When logging in to a VBASE runtime project via Web-Remote, the product uses XOR with a static initial key to obfuscate login messages. An unauthenticated remote attacker with the ability to capture a login session can obtain the login credentials.