Insecure storage of password in easySoft
CVE-2023-43777

5.9MEDIUM

Key Information:

Vendor
Eaton
Status
Vendor
CVE Published:
17 October 2023

Summary

Eaton easySoft software is used to program easy controllers and displays for configuring, programming and defining parameters for all the intelligent relays. This software has a password protection functionality to secure the project file from unauthorized access. This password was being stored insecurely and could be retrieved by skilled adversaries. 

Affected Version(s)

easySoft 0

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Manuel Stotz (SySS GmbH)
.
CVE-2023-43777 : Insecure storage of password in easySoft | SecurityVulnerability.io