Echelon SmartServer 2.2 with i.LON Vision 2.2 stores cleartext credentials in a file, which could allow an attacker to obtain cleartext usernames and passwords of the SmartServer. If the attacker obtains the file, then the credentials could be used to control the web user interface and file transfer protocol (FTP) server.
oryginał ENCVSS Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:HEchelon I.lon Vision
APPEchelon2.2Echelon Smartserver
HWEchelon2.2
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Powiązane podatności
CVE-2018-10627CRITICAL9.8PL ✓ten sam vendor
Nieuprawniony dostęp przez SOAP API w urządzeniach Echelon SmartServer i i.LON
CVE-2018-8851CRITICAL9.8PL ✓ten sam vendor
Echelon SmartServer/i.LON — przechowywanie haseł w postaci jawnej
CVE-2018-8855CRITICAL9.8PL ✓ten sam vendor
Echelon SmartServer / i.LON — niezaszyfrowana komunikacja Web i FTP
CVE-2018-8859CRITICAL9.8PL ✓ten sam vendor
Echelon SmartServer / i.LON — obejście uwierzytelnienia przez manipulację ścieżką