CVE-2022-3089

Echelon SmartServer 2.2 with i.LON Vision 2.2 stores cleartext credentials in a file, which could allow an attacker to obtain cleartext usernames and passwords of the SmartServer. If the attacker obtains the file, then the credentials could be used to control the web user interface and file transfer protocol (FTP) server.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:echelon:i.lon_vision:2.2:*:*:*:*:*:*:*
cpe:2.3:h:echelon:smartserver:2.2:*:*:*:*:*:*:*

History

21 Nov 2024, 07:18

Type Values Removed Values Added
References () https://www.cisa.gov/uscert/ics/advisories/icsa-23-037-01 - Broken Link () https://www.cisa.gov/uscert/ics/advisories/icsa-23-037-01 - Broken Link
CVSS v2 : unknown
v3 : 9.8
v2 : unknown
v3 : 6.3
Summary
  • (es) Echelon SmartServer 2.2 con i.LON Vision 2.2 almacena las credenciales en texto plano en un archivo, lo que podría permitir a un atacante obtener nombres de usuario y contraseñas en texto plano del SmartServer. Si el atacante obtiene el archivo, las credenciales podrían usarse para controlar la interfaz de usuario web y el servidor del protocolo de transferencia de archivos (FTP).

07 Nov 2023, 03:50

Type Values Removed Values Added
Summary Echelon SmartServer 2.2 with i.LON Vision 2.2 stores cleartext credentials in a file, which could allow an attacker to obtain cleartext usernames and passwords of the SmartServer. If the attacker obtains the file, then the credentials could be used to control the web user interface and file transfer protocol (FTP) server. Echelon SmartServer 2.2 with i.LON Vision 2.2 stores cleartext credentials in a file, which could allow an attacker to obtain cleartext usernames and passwords of the SmartServer. If the attacker obtains the file, then the credentials could be used to control the web user interface and file transfer protocol (FTP) server.

Information

Published : 2023-02-13 17:15

Updated : 2024-11-21 07:18


NVD link : CVE-2022-3089

Mitre link : CVE-2022-3089

CVE.ORG link : CVE-2022-3089


JSON object : View

Products Affected

echelon

  • i.lon_vision
  • smartserver
CWE
CWE-798

Use of Hard-coded Credentials

CWE-312

Cleartext Storage of Sensitive Information