Centralny Instytut Ochrony Pracy STER Unencrypted TCP Traffic Vulnerability Allowing Man-In-The-Middle Attacks

Vulnerability

A vulnerability exists in the STER software developed by the Centralny Instytut Ochrony Pracy - Państwowy Instytut Badawczy, affecting all versions prior to 9.5. The issue arises from the use of unencrypted TCP traffic for data transmission, which allows attackers to conduct Man-In-The-Middle attacks and intercept sensitive information such as passwords, personal data, and authentication tokens.

Impact

Exploitation of this vulnerability could lead to unauthorized interception of sensitive data, including passwords, personal information, and authentication tokens.

Remediation

Users can upgrade to STER version 9.5 or later to address this vulnerability.

Added: May 22, 2026, 10:24 AM
Updated: May 22, 2026, 10:24 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
6.0
remediation
0.0
relevance
9.0
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.