PT-2019-5399 · Schneider Electric · Easergy Builder
Published
2019-08-21
·
Updated
2021-12-11
·
CVE-2020-7515
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Easergy Builder versions 1.4.7.2 and prior
Description
A vulnerability exists due to the use of a hard-coded cryptographic key stored in cleartext, which could allow an attacker to decrypt passwords. This issue is related to the storage of the cryptographic key in an unencrypted form, potentially enabling an attacker to access user passwords.
Recommendations
For Easergy Builder versions 1.4.7.2 and prior, consider updating to a version that does not use hard-coded cryptographic keys in cleartext, or apply additional security measures to protect against password decryption attacks. As a temporary workaround, restrict access to sensitive areas of the system to minimize the risk of exploitation.
Fix
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Easergy Builder