PT-2022-3181 · Unknown · Stardom Fcn Controller
Published
2022-06-21
·
Updated
2022-07-08
·
CVE-2022-29519
CVSS v2.0
7.9
High
| Vector | AV:A/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
STARDOM FCN Controller and FCJ Controller versions R1.01 through R4.31
Description
The issue is related to the storage of credentials in plaintext and the transmission of sensitive information in cleartext. This could allow a remote attacker to gain unauthorized access to the device. An adjacent attacker may be able to login to the affected products, alter device configuration settings, or tamper with device firmware.
Recommendations
For versions R1.01 through R4.31, consider restricting access to the device to minimize the risk of exploitation until a patch is available.
As a temporary workaround, avoid using the affected products for sensitive operations until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Cleartext Transmission of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Stardom Fcn Controller