PT-2022-17086 · Hitachi Energy · Pcm600
Published
2022-11-22
·
Updated
2024-05-28
·
CVE-2022-2513
CVSS v3.1
7.1
High
| Vector | AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Hitachi Energy’s PCM600 product (affected versions not specified)
Description
A vulnerability exists in the Intelligent Electronic Device (IED) Connectivity Package (ConnPack) credential storage function, where IEDs credentials are stored in a cleartext format in the database and logs files. An attacker having access to the exported backup file can exploit the vulnerability and obtain user credentials of the IEDs. Additionally, an attacker with administrator access to the host machine can obtain other user credentials by analyzing database log files. The credentials may be used to perform unauthorized modifications such as loading incorrect configurations, rebooting the IEDs, or causing a denial-of-service on the IEDs.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Cleartext Storage of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pcm600