Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vgvm-464w-97h8

Опубликовано: 01 сент. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.9

Описание

All versions of LS Industrial Systems (LSIS) Co. Ltd LS Electric PLCs and XG5000 PLC programming software are affected where passwords are not adequately encrypted during the communication process between the XG5000 software and the affected PLC. This would allow an attacker to identify and decrypt the affected PLC’s password by sniffing the traffic.

All versions of LS Industrial Systems (LSIS) Co. Ltd LS Electric PLCs and XG5000 PLC programming software are affected where passwords are not adequately encrypted during the communication process between the XG5000 software and the affected PLC. This would allow an attacker to identify and decrypt the affected PLC’s password by sniffing the traffic.

EPSS

Процентиль: 30%
0.0011
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-326

Связанные уязвимости

CVSS3: 6.5
nvd
больше 3 лет назад

Passwords are not adequately encrypted during the communication process between all versions of LS Industrial Systems (LSIS) Co. Ltd LS Electric XG5000 software prior to V4.0 and LS Electric PLCs: all versions of XGK-CPUU/H/A/S/E prior to V3.50, all versions of XGI-CPUU/UD/H/S/E prior to V3.20, all versions of XGR-CPUH prior to V1.80, all versions of XGB-XBMS prior to V3.00, all versions of XGB-XBCH prior to V1.90, and all versions of XGB-XECH prior to V1.30. This would allow an attacker to identify and decrypt the password of the affected PLCs by sniffing the PLC’s communication traffic.

EPSS

Процентиль: 30%
0.0011
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-326