CVE-2023-2809: Use of Cleartext credentials in Sage 200 Spain
Plaintext credential usage vulnerability in Sage 200 Spain 2023.38.001 version, the exploitation of which could allow a remote attacker to extract SQL database credentials from the DLL application. This vulnerability could be linked to known techniques to obtain remote execution of MS SQL commands and escalate privileges on Windows systems because the credentials are stored in plaintext.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2023-2809.
What is the title of the vulnerability?
The title of the vulnerability is 'Plaintext credential usage vulnerability in Sage 200 Spain 2023.38.001 version the exploitation of w…'.
What is the severity of CVE-2023-2809?
The severity of CVE-2023-2809 is critical with a CVSS (Common Vulnerability Scoring System) score of 9.8.
Which software version is affected by CVE-2023-2809?
The Sage 200 Spain version 2023.38.001 is affected by CVE-2023-2809.
How can a remote attacker exploit CVE-2023-2809?
A remote attacker can exploit CVE-2023-2809 to extract SQL database credentials from the DLL application.