PT-2019-5399 · Schneider Electric · Easergy Builder
Publicado
2019-08-21
·
Atualizado
2021-12-11
·
CVE-2020-7515
CVSS v3.1
7.8
Alta
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Easergy Builder versions 1.4.7.2 and prior
Description
A vulnerability exists due to the use of a hard-coded cryptographic key stored in cleartext, which could allow an attacker to decrypt passwords. This issue is related to the storage of the cryptographic key in an unencrypted form, potentially enabling an attacker to access user passwords.
Recommendations
For Easergy Builder versions 1.4.7.2 and prior, consider updating to a version that does not use hard-coded cryptographic keys in cleartext, or apply additional security measures to protect against password decryption attacks. As a temporary workaround, restrict access to sensitive areas of the system to minimize the risk of exploitation.
Correção
Using Hardcoded Credentials
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Easergy Builder