ZIV 4CCT-EA6-334126BF
cpe:2.3:h:zivautomation:4cct-ea6-334126bf:*:*:*:*:*:*:*, +1 more
- 3.23.80.27.36371
- 3.23.77.8.33251
A vulnerability exists in ZIV devices that exposes authentication credentials for the device's web server. The credentials are transmitted in base64 encoding within the HTTP headers. Since base64 is not a secure encryption method, an attacker could intercept the web request during the login process and retrieve the credentials.
Exploitation of this vulnerability allows for unauthorized access to the device's web server, potentially leading to further actions based on the access rights of the authenticated user.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.