Firmware Binary Leaks Test Credentials
CVE-2024-8070
8.5HIGH
Key Information:
- Vendor
Schneider Electric
- Vendor
- CVE Published:
- 13 October 2024
What is CVE-2024-8070?
A vulnerability exists within Schneider Electric's firmware due to the cleartext storage of sensitive information. This issue particularly affects the handling of test credentials, which can be exposed within the firmware binary. Adversaries exploiting this vulnerability may gain unauthorized access to these credentials, leading to potential security breaches and unauthorized control over affected devices. Addressing this security flaw is essential to enhance the overall security posture of Schneider Electric's products and mitigate the associated risks.
Affected Version(s)
EVlink Home Smart All versions prior to 2.0.6.0.0
Schneider Charge All versions prior to 1.13.4