QSearchQSearch

CVE-2017-14852

8.6 HIGH

An insecure communication was found between a user and the Orpak SiteOmat management console for all known versions, due to an invalid SS...

Published: 2019-06-03 · Last updated: 2026-06-02

Severity and scoring

CVSS
8.6 HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
CWE
CWE-310, CWE-311

Affected products

VendorProduct
orpaksiteomat

Description

An insecure communication was found between a user and the Orpak SiteOmat management console for all known versions, due to an invalid SSL certificate. The attack allows for an eavesdropper to capture the communication and decrypt the data.

Source: NVD

References

Related CVEs

Same vendor

  • CVE-2017-14854 A stack buffer overflow exists in one of the Orpak SiteOmat CGI components, allowing for remote code execution (9.1 CRITICAL)
  • CVE-2017-14853 The Orpak SiteOmat OrCU component is vulnerable to code injection, for all versions prior to 2017-09-25, due to a search query that uses ... (8.6 HIGH)
  • CVE-2017-14851 A SQL injection vulnerability exists in all Orpak SiteOmat versions prior to 2017-09-25 (9.8 CRITICAL)
  • CVE-2017-14850 All known versions of the Orpak SiteOmat web management console is vulnerable to multiple instances of Stored Cross-site Scripting due to... (6.1 MEDIUM)
  • CVE-2017-14728 An authentication bypass was found in an unknown area of the SiteOmat source code (9.8 CRITICAL)

Same CWE

  • CVE-2026-53442 Jenkins 2.567 and earlier, LTS 2.555.2 and earlier does not encrypt secrets from POST config.xml submissions before storing them in job c... (5.3 MEDIUM)
  • CVE-2026-49000 An insecure password scheme refers to vulnerabilities arising from improper selection of encryption algorithms, inadequate key management... (7.0 HIGH)
  • CVE-2026-34486 Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptI... (7.5 HIGH)
  • CVE-2025-13453 A potential vulnerability was reported in some ThinkPlus USB drives that could allow a user with physical access to read data stored on t... (4.6 MEDIUM)
  • CVE-2020-7567 A CWE-311: Missing Encryption of Sensitive Data vulnerability exists in Modicon M221 (all references, all versions) that could allow the ... (5.7 MEDIUM)