CVE-2023-41965
Sending some requests in the web application of the vulnerable device allows information to be obtained due to the lack of security in the authentication process.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.5
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS probability
- 0.12%
- CWE
- CWE-921
- Published
- 2023-09-18
- Last modified
- 2026-03-13
Affected products
- Socomec MODULYS GP (MOD3GP-SY-120K)
Weakness type
Related vulnerabilities
- CVE-2025-30016 — Authentication Bypass Vulnerability in SAP Financial Consolidation
- CVE-2025-24843 — Dario Health USB-C Blood Glucose Monitoring System Starter Kit Android Application Storage of Sensitive Data in a Mechanism without Access Control
- CVE-2024-9334 — Information Disclosure in E-Kent's Pallium Vehicle Tracking
- CVE-2025-24870 — Insecure Key & Secret Management vulnerability in SAP GUI for Windows
- CVE-2024-5206 — Sensitive Data Leakage in sklearn.feature_extraction.text.TfidfVectorizer in scikit-learn/scikit-learn
- CVE-2023-41818
- CVE-2023-2665 — Storage of Sensitive Data in a Mechanism without Access Control in francoisjacquet/rosariosis
- CVE-2021-27456 — Philips Gemini PET/CT Storage of Sensitive Data in a Mechanism Without Access Control