Econolite EOS versions prior to 3.2.23 lack a password
requirement for gaining “READONLY” access to log files and certain database and
configuration files. One such file contains tables with MD5 hashes and
usernames for all defined users in the control software, including
administrators and technicians.
References
Link | Resource |
---|---|
https://www.cisa.gov/uscert/ics/advisories/icsa-23-026-02 | Third Party Advisory US Government Resource |
https://www.cisa.gov/uscert/ics/advisories/icsa-23-026-02 | Third Party Advisory US Government Resource |
Configurations
History
21 Nov 2024, 07:37
Type | Values Removed | Values Added |
---|---|---|
References | () https://www.cisa.gov/uscert/ics/advisories/icsa-23-026-02 - Third Party Advisory, US Government Resource | |
Summary |
|
20 Jun 2023, 16:15
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-284 | |
Summary | Econolite EOS versions prior to 3.2.23 lack a password requirement for gaining “READONLY” access to log files and certain database and configuration files. One such file contains tables with MD5 hashes and usernames for all defined users in the control software, including administrators and technicians. |
Information
Published : 2023-01-26 21:18
Updated : 2024-11-21 07:37
NVD link : CVE-2023-0451
Mitre link : CVE-2023-0451
CVE.ORG link : CVE-2023-0451
JSON object : View
Products Affected
econolite
- eos
CWE