CVE-2023-0451

Econolite EOS versions prior to 3.2.23 lack a password requirement for gaining “READONLY” access to log files and certain database and configuration files. One such file contains tables with MD5 hashes and usernames for all defined users in the control software, including administrators and technicians.
References
Link Resource
https://www.cisa.gov/uscert/ics/advisories/icsa-23-026-02 Third Party Advisory US Government Resource
https://www.cisa.gov/uscert/ics/advisories/icsa-23-026-02 Third Party Advisory US Government Resource
Configurations

Configuration 1 (hide)

cpe:2.3:a:econolite:eos:*:*:*:*:*:*:*:*

History

21 Nov 2024, 07:37

Type Values Removed Values Added
References () https://www.cisa.gov/uscert/ics/advisories/icsa-23-026-02 - Third Party Advisory, US Government Resource () https://www.cisa.gov/uscert/ics/advisories/icsa-23-026-02 - Third Party Advisory, US Government Resource
Summary
  • (es) Las versiones de Econolite EOS anteriores a la 3.2.23 carecen de un requisito de contraseña para obtener acceso "SÓLO LECTURA" a los archivos de registro y a determinadas bases de datos y archivos de configuración. Uno de esos archivos contiene tablas con hash MD5 y nombres de usuario para todos los usuarios definidos en el software de control, incluidos administradores y técnicos.

20 Jun 2023, 16:15

Type Values Removed Values Added
CWE NVD-CWE-Other CWE-284
Summary All versions of Econolite EOS traffic control software are vulnerable to CWE-284: Improper Access Control, and lack a password requirement for gaining “READONLY” access to log files, as well as certain database and configuration files. One such file contains tables with message-digest algorithm 5 (MD5) hashes and usernames for all defined users in the control software, including administrators and technicians. Econolite EOS versions prior to 3.2.23 lack a password requirement for gaining “READONLY” access to log files and certain database and configuration files. One such file contains tables with MD5 hashes and usernames for all defined users in the control software, including administrators and technicians.

Information

Published : 2023-01-26 21:18

Updated : 2024-11-21 07:37


NVD link : CVE-2023-0451

Mitre link : CVE-2023-0451

CVE.ORG link : CVE-2023-0451


JSON object : View

Products Affected

econolite

  • eos
CWE
CWE-284

Improper Access Control

NVD-CWE-Other