Permalink
CVE-2026-0393
6.9 MEDIUM
- CVSS version (CVSS): 4.0
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Attack Requirement (AT): None (N)
- Privileges Required (PR): Low (L)
- User Interaction (UI): Passive (P)
- Vulnerable System Impact Confidentiality (VC): High (H)
- Vulnerable System Impact Integrity (VI): None (N)
- Vulnerable System Impact Availability (VA): None (N)
- Subsequent System Impact Confidentiality (SC): None (N)
- Subsequent System Impact Integrity (SI): None (N)
- Subsequent System Impact Availability (SA): None (N)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Attack Requirement (MAT): None (N)
- Modified Privileges Required (MPR): Low (L)
- Modified User Interaction (MUI): Passive (P)
- Modified Vulnerable System Impact Confidentiality (MVC): High (H)
- Modified Vulnerable System Impact Integrity (MVI): None (N)
- Modified Vulnerable System Impact Availability (MVA): None (N)
- Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
- Modified Subsequent System Impact Integrity (MSI): Negligible (N)
- Modified Subsequent System Impact Availability (MSA): Negligible (N)
- Safety (S): Not Defined (X)
- Automatable (AU): Not Defined (X)
- Recovery (R): Not Defined (X)
- Value Density (V): Not Defined (X)
- Vulnerability Response Effort (RE): Not Defined (X)
- Provider Urgency (U): Not Defined (X)
- Confidentiality Req. (CR): Not Defined (X)
- Integrity Req. (IR): Not Defined (X)
- Availability Req. (AR): Not Defined (X)
- Exploit Maturity (E): Not Defined (X)
Activity log
- Created suggestion
CODESYS Visualization - Insufficiently Protected Credentials
The affected product may expose credentials remotely between low privileged visualization users during concurrent login operations due to insufficient isolation of authentication data. The vulnerability affects only login operations within an active visualization session.
References
Affected products
Visualization
- <4.10.0.0
Matching in nixpkgs
pkgs.kodiPackages.visualization-goom
Goom visualization for kodi
pkgs.kodiPackages.visualization-matrix
Matrix visualization for kodi
pkgs.kodiPackages.visualization-fishbmc
FishBMC visualization for kodi
pkgs.kodiPackages.visualization-projectm
Projectm visualization for kodi
pkgs.kodiPackages.visualization-spectrum
Spectrum visualization for kodi
pkgs.kodiPackages.visualization-waveform
Waveform visualization for kodi
pkgs.kodiPackages.visualization-pictureit
PictureIt visualization for kodi
pkgs.kodiPackages.visualization-shadertoy
Shadertoy visualization for kodi
pkgs.kodiPackages.visualization-starburst
Starburst visualization for kodi
pkgs.python312Packages.pyqtdatavisualization
Python bindings for the Qt Data Visualization library
pkgs.python313Packages.pyqtdatavisualization
Python bindings for the Qt Data Visualization library
pkgs.python314Packages.pyqtdatavisualization
Python bindings for the Qt Data Visualization library
Package maintainers
-
@aanderse Aaron Andersen <aaron@fosslib.net>
-
@dschrempf Dominik Schrempf <dominik.schrempf@gmail.com>
-
@peterhoeg Peter Hoeg <peter@hoeg.com>
-
@minijackson Rémi Nicole <minijackson@riseup.net>
-
@nvmd Sergey Kazenyuk <kazenyuk@pm.me>
-
@cpages Carles Pagès <page@ruiec.cat>
-
@panicgh Nicolas Benes <nbenes.gh@xandea.de>