PT-2022-3550 · Da50N · Da50N

Ron Brash

·

Published

2022-04-14

·

Updated

2022-04-28

·

CVE-2022-27179

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions DA50N (affected versions not specified)
Description The issue is related to insufficient protection of registration data in the web interface, which may allow a remote attacker to gain unauthorized access to protected information. A malicious actor having access to the exported configuration file may obtain the stored credentials and thereby gain access to the protected resource. If the same passwords were used for other resources, further such assets may be compromised.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Insufficiently Protected Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-04334
CVE-2022-27179

Affected Products

Da50N