7.1
CVE-2012-1977
- EPSS 0.8%
- Veröffentlicht 09.05.2012 10:33:15
- Zuletzt bearbeitet 16.06.2026 23:40:43
- Quelle ics-cert@hq.dhs.gov
- CVE-Watchlists
- Unerledigt
WellinTech KingSCADA Missing Encryption of Sensitive Data
WellinTech KingSCADA 3.0 uses a cleartext base64 format for storage of passwords in user.db, which allows context-dependent attackers to obtain sensitive information by reading this file.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Wellintech ≫ Kingview Version3.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.8% | 0.517 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.1 | 8.6 | 6.9 |
AV:N/AC:M/Au:N/C:C/I:N/A:N
|
| ics-cert@hq.dhs.gov | 7.1 | 8.6 | 6.9 |
AV:N/AC:M/Au:N/C:C/I:N/A:N
|
CWE-311 Missing Encryption of Sensitive Data
The product does not encrypt sensitive or critical information before storage or transmission.
http://dsecrg.com/pages/vul/show.php?id=405
http://www.us-cert.gov/control_systems/pdf/ICSA-12-129-01.pdf
https://www.cisa.gov/news-events/ics-advisories/icsa-12-129-01