Echelon SmartServer 2.2 with i.LON Vision 2.2 stores cleartext credentials in a file, which could allow an attacker to obtain cleartext usernames and passwords of the SmartServer. If the attacker obtains the file, then the credentials could be used to control the web user interface and file transfer protocol (FTP) server.
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:HEchelon I.lon Vision
APPEchelon2.2Echelon Smartserver
HWEchelon2.2
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Related vulnerabilities
CVE-2018-10627CRITICAL9.8PL ✓same vendor
Nieuprawniony dostęp przez SOAP API w urządzeniach Echelon SmartServer i i.LON
CVE-2018-8851CRITICAL9.8PL ✓same vendor
Echelon SmartServer/i.LON — przechowywanie haseł w postaci jawnej
CVE-2018-8855CRITICAL9.8PL ✓same vendor
Echelon SmartServer / i.LON — niezaszyfrowana komunikacja Web i FTP
CVE-2018-8859CRITICAL9.8PL ✓same vendor
Echelon SmartServer / i.LON — obejście uwierzytelnienia przez manipulację ścieżką