CVE-2022-2569

MEDIUM

Arcinformatique PCVue <= 12.0.27 - Cleartext Storage of Sensitive Information

Title source: llm
STIX 2.1

Description

The affected device stores sensitive information in cleartext, which may allow an authenticated user to access session data stored in the OAuth database belonging to legitimate users

References (1)

Core 1
Core References
Patch, Third Party Advisory, US Government Resource x_refsource_misc
https://www.cisa.gov/uscert/ics/advisories/icsa-22-235-01-0

Scores

CVSS v3 5.5
EPSS 0.0013
EPSS Percentile 2.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-312
Status published
Products (1)
arcinformatique/pcvue < 12.0.27
Published Aug 24, 2022
Tracked Since Feb 18, 2026