7.1

CVE-2012-1977

WellinTech KingSCADA Missing Encryption of Sensitive Data

WellinTech KingSCADA 3.0 uses a cleartext base64 format for storage of passwords in user.db, which allows context-dependent attackers to obtain sensitive information by reading this file.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
WellintechKingview Version3.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.8% 0.517
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.1 8.6 6.9
AV:N/AC:M/Au:N/C:C/I:N/A:N
ics-cert@hq.dhs.gov 7.1 8.6 6.9
AV:N/AC:M/Au:N/C:C/I:N/A:N
CWE-311 Missing Encryption of Sensitive Data

The product does not encrypt sensitive or critical information before storage or transmission.

http://dsecrg.com/pages/vul/show.php?id=405
http://www.us-cert.gov/control_systems/pdf/ICSA-12-129-01.pdf
Third Party Advisory
US Government Resource
https://www.cisa.gov/news-events/ics-advisories/icsa-12-129-01