PT-2012-3707 · Wellintech · Kingscada
Published
2012-05-09
·
Updated
2025-06-26
·
CVE-2012-1977
CVSS v2.0
7.1
High
| Vector | AV:N/AC:M/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
WellinTech KingSCADA version 3.0
Description
The issue concerns the storage of passwords in a cleartext base64 format within the user.db file, allowing attackers to obtain sensitive information by reading this file.
Recommendations
For WellinTech KingSCADA version 3.0, consider encrypting the passwords stored in the user.db file to prevent unauthorized access to sensitive information. As a temporary workaround, restrict access to the user.db file to minimize the risk of exploitation.
Fix
Missing Encryption of Sensitive Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Kingscada