Plaintext Password Storage Vulnerability in CONPROSYS nano Series by CONTEC
CVE-2026-82783

4.1MEDIUM

What is CVE-2026-82783?

A security flaw exists in the CONPROSYS nano Series which involves the inadvertent storage of passwords in plaintext. This vulnerability could allow an attacker with physical access to the device to extract sensitive credentials, potentially leading to unauthorized access or control over the device. It is crucial for users of the affected products to review their security protocols and implement safeguards to mitigate potential risks.

Affected Version(s)

Programmable Remote I/O Coupler Unit (Software PLC Type) CPSN-PCB271-S1-041 0 < 1.61

Remote I/O Coupler Unit (EtherNet/IP Adapter) CPSN-EOB471EI-[]1 0 < 1.02

Remote I/O Coupler Unit (Server Type) CPSN-MCB271-* 0 < 1.82

References

CVSS V4

Score:
4.1
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Physical
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.