PcVue
cpe:2.3:a:pcvuesolutions:pcvue:*:*:*:*:*:*:*
- >= 12.0.0, <= 16.3.3
A vulnerability exists in the OAuth Resource Owner Password Credentials (ROPC) flow, which is still utilized by the web services for WebVue, WebScheduler, TouchVue, and Snapvue features in PcVue versions 12.0.0 to 16.3.3. This vulnerability arises from the continued use of a deprecated OAuth flow, potentially allowing remote attackers to steal user credentials.
Exploitation of this vulnerability could lead to unauthorized credential theft, allowing attackers to impersonate users.
Users can upgrade to PcVue version 16.3.4 or 15.2.14 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.