PT-2023-13022 · Echelon · Echelon Smartserver+1

·

CVE-2022-3089

·

Publicado

2023-02-13

·

Atualizado

2023-02-25

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Echelon SmartServer version 2.2 with i.LON Vision 2.2
Description The issue allows an attacker to obtain cleartext usernames and passwords of the SmartServer by accessing a file that stores credentials in cleartext. If the attacker obtains the file, the credentials could be used to control the web user interface and file transfer protocol (FTP) server.
Recommendations For Echelon SmartServer version 2.2 with i.LON Vision 2.2, consider restricting access to the file that stores cleartext credentials to minimize the risk of exploitation. As a temporary workaround, limit access to the web user interface and FTP server until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Using Hardcoded Credentials

Cleartext Storage of Sensitive Information

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2022-3089

Produtos afetados

Echelon Smartserver
I.Lon Vision