Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c3h6-c9ph-wrhw

Опубликовано: 01 июн. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 8.1

Описание

Plaintext storage of a password exists in CONPROSYS HMI System (CHS) versions prior to 3.5.3. Because account information of the database is saved in a local file in plaintext, a user who can access the PC where the affected product is installed can obtain the information. As a result, information in the database may be obtained and/or altered by the user.

Plaintext storage of a password exists in CONPROSYS HMI System (CHS) versions prior to 3.5.3. Because account information of the database is saved in a local file in plaintext, a user who can access the PC where the affected product is installed can obtain the information. As a result, information in the database may be obtained and/or altered by the user.

EPSS

Процентиль: 26%
0.00092
Низкий

8.1 High

CVSS3

Дефекты

CWE-312

Связанные уязвимости

CVSS3: 8.1
nvd
больше 2 лет назад

Plaintext storage of a password exists in CONPROSYS HMI System (CHS) versions prior to 3.5.3. Because account information of the database is saved in a local file in plaintext, a user who can access the PC where the affected product is installed can obtain the information. As a result, information in the database may be obtained and/or altered by the user.

CVSS3: 5.5
fstec
больше 2 лет назад

Уязвимость HMI/SCADA CONPROSYS HMI, связанная с хранением учетных данных в виде открытого текста, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 26%
0.00092
Низкий

8.1 High

CVSS3

Дефекты

CWE-312