OpenPLC_V3 is vulnerable to a Plaintext Storage of a Password vulnerability that could allow an attacker to retrieve credentials and access sensitive information.
According to CWE-256, the application stores passwords in an unsecured manner — in plaintext — instead of using secure mechanisms such as salted hashing. An attacker who gains access to the file system, database, or device memory can directly read authentication credentials without needing to crack them. The attack vector is network-based and does not require prior authentication or user interaction, although specific environmental conditions may be necessary for exploitation (AT:P).
An attacker can recover user authentication credentials (login and password) of the system and gain unauthorized access to sensitive functions and information managed by the OpenPLC V3 controller. Credential compromise in an industrial environment can lead to takeover of automation processes.
Apply patches available from the manufacturer according to references. Additionally, it is recommended to: isolate OT/ICS networks from corporate networks and the Internet, restrict access to the OpenPLC management interface to trusted hosts only, and monitor attempts of unauthorized access. Detailed recommendations are contained in the CISA advisory at https://www.cisa.gov/news-events/ics-advisories/icsa-25-345-10.
OpenPLC V3 Firmware and OpenPLC V3 (products: Openplcproject Openplc V3 Firmware, Openplcproject Openplc V3); specific versions indicated in manufacturer references and CISA ICS-CERT advisory ICSA-25-345-10.
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XOpenplcproject Openplc V3
HWOpenplcprojectall versionsOpenplcproject Openplc V3 Firmware
OSOpenplcprojectall versions
Related vulnerabilities
OpenPLC V3 — pominięcie uwierzytelnienia przez niezabezpieczoną domyślną inicjalizację
Stack-based buffer overflow w OpenPLC V3 — RCE przez EtherNet/IP
Buffer overflow w OpenPLC V2/V3 — funkcja mapUnusedIO() w modbus.cpp
OpenPLC_V3 REST API endpoint checks for JWT presence but never verifies the caller's role. Any authenticated u...
An out-of-bounds read vulnerability exists in the OpenPLC Runtime EtherNet/IP PCCC parser functionality of Ope...