SOCOMEC MODULYS GP Netvision versions 7.20 and prior lack strong encryption for credentials on HTTP connections, which could result in threat actors obtaining sensitive information.
Credits
Javier Fernandez Beré and Aarón Flecha Menéndez of S21sec reported this vulnerability to CISA.