Fuji Electric V-Server before 6.0.33.0 stores database credentials in project files as plaintext. An attacker that can gain access to the project file can recover the database credentials and gain access to the database server.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HFujielectric V Server
APPFujielectric< 6.0.33.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
Related vulnerabilities
CVE-2019-18240CRITICAL9.8PL ✓same product
Heap-based buffer overflow w Fuji Electric V-Server umożliwia RCE
CVE-2018-14809CRITICAL9.8PL ✓same product
Use-after-free w Fuji Electric V-Server umożliwiający RCE
CVE-2018-14811CRITICAL9.8PL ✓same product
RCE przez untrusted pointer dereference w Fuji Electric V-Server
CVE-2018-14813CRITICAL9.8PL ✓same product
Heap-based buffer overflow umożliwiający RCE w Fuji Electric V-Server
CVE-2018-14815CRITICAL9.8PL ✓same product
RCE poprzez out-of-bounds write w Fuji Electric V-Server