MEDIUM🇬🇧 English

CVE-2026-1693

CVSS 5.3v4.0pub. 2026-02-26upd. 2026-07-09

Przepływ OAuth grant type Resource Owner Password Credentials (ROPC) jest wciąż używany przez usługi webowe wykorzystywane przez funkcje WebVue, WebScheduler, TouchVue i Snapvue w PcVue w wersjach od 12.0.0 do 16.3.3 włącznie, pomimo że jest przestarzały. Może to umożliwić zdalnemu atakującemu kradzież poświadczeń użytkownika.

Pokaż oryginał (EN)

The OAuth grant type Resource Owner Password Credentials (ROPC) flow is still used by the werbservices used by the WebVue, WebScheduler, TouchVue and Snapvue features of PcVue in version 12.0.0 through 16.3.3 included despite being deprecated. It might allow a remote attacker to steal user credentials.

CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:X/RE:M/U:Clear
  • Arcinfo Pcvue

    APP
    Arcinfo
    12.0.0 – 15.2.1316.0.0 – 16.3.4 (bez)
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
CWE
Referencje

Powiązane podatności

CVE-2020-26867CRITICAL9.8PL ✓ten sam produkt

RCE poprzez deserializację niezaufanych danych w ARC Informatique PcVue

CVE-2026-14868HIGH8.4PL ✓ten sam produkt

Słaby algorytm szyfrowania konfiguracji kont w PcVue

CVE-2020-26868HIGH7.5ten sam produkt

ARC Informatique PcVue prior to version 12.0.17 is vulnerable to a denial-of-service attack due to the ability...

CVE-2020-26869HIGH7.5ten sam produkt

ARC Informatique PcVue prior to version 12.0.17 is vulnerable to information exposure, allowing unauthorized u...

CVE-2011-4042HIGH9.3ten sam produkt

An unspecified ActiveX control in SVUIGrd.ocx in ARC Informatique PcVue 6.0 through 10.0, FrontVue, and PlantV...