HIGH🇵🇱 Wersja polska

CVE-2019-11369

CVSS 8.8v3.0pub. 2019-06-03upd. 2024-11-21

An issue was discovered in Carel pCOWeb prior to B1.2.4. In /config/pw_changeusers.html the device stores cleartext passwords, which may allow sensitive information to be read by someone with access to the device.

CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • Carel Pcoweb Card

    HW
    Carel
    all versions
  • Carel Pcoweb Card Firmware

    OS
    Carel
    < b1.2.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2022-37122HIGH7.5same product

Carel pCOWeb HVAC BACnet Gateway 2.1.0, Firmware: A2.1.0 - B2.1.0, Application Software: 2.15.4A Software v16 ...

CVE-2019-9484HIGH7.5same product

The Glen Dimplex Deutschland GmbH implementation of the Carel pCOWeb configuration tool allows remote attacker...

CVE-2019-11370MEDIUM5.4same product

Stored XSS was discovered in Carel pCOWeb prior to B1.2.4, as demonstrated by the config/pw_snmp.html "System ...

CVE-2022-34827CRITICAL9.9PL ✓same vendor

Nieprawidłowa kontrola dostępu w Carel Boss Mini 1.5.0

CVE-2019-13553CRITICAL9.8PL ✓same vendor

Hardcoded credentials w Rittal Chiller SK 3232 / Carel pCOWeb