PT-2022-3181 · Unknown · Stardom Fcn Controller

Published

2022-06-21

·

Updated

2022-07-08

·

CVE-2022-29519

CVSS v2.0

7.9

High

VectorAV:A/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions STARDOM FCN Controller and FCJ Controller versions R1.01 through R4.31
Description The issue is related to the storage of credentials in plaintext and the transmission of sensitive information in cleartext. This could allow a remote attacker to gain unauthorized access to the device. An adjacent attacker may be able to login to the affected products, alter device configuration settings, or tamper with device firmware.
Recommendations For versions R1.01 through R4.31, consider restricting access to the device to minimize the risk of exploitation until a patch is available. As a temporary workaround, avoid using the affected products for sensitive operations until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Cleartext Transmission of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-03861
CVE-2022-29519

Affected Products

Stardom Fcn Controller