PT-2020-2068 · Yokogawa · Tristation 1131
Published
2020-04-14
·
Updated
2021-11-08
·
CVE-2020-7483
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
TriStation 1131 versions prior to v4.9.1
Description
A vulnerability could cause certain data to be visible on the network when the
password feature is enabled. This feature is an additional optional check performed by TS1131 to verify its connection to a specific controller. The data is sent as clear text and is visible on the network. The vulnerability allows a remote attacker to gain unauthorized access to protected information.Recommendations
For versions prior to v4.9.1, consider disabling the
password feature until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability, however versions v4.9.1 and later do not have this vulnerability.Fix
Cleartext Transmission of Sensitive Information
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Tristation 1131