7.1
CVE-2012-1977
- EPSS 0.26%
- Veröffentlicht 09.05.2012 10:33:15
- Zuletzt bearbeitet 26.06.2025 22:15:24
- Quelle ics-cert@hq.dhs.gov
- CVE-Watchlists
- Unerledigt
WellinTech KingSCADA 3.0 uses a cleartext base64 format for storage of passwords in user.db, which allows context-dependent attackers to obtain sensitive information by reading this file.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Wellintech ≫ Kingview Version3.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.26% | 0.491 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.1 | 8.6 | 6.9 |
AV:N/AC:M/Au:N/C:C/I:N/A:N
|
| ics-cert@hq.dhs.gov | 7.1 | 8.6 | 6.9 |
AV:N/AC:M/Au:N/C:C/I:N/A:N
|
CWE-311 Missing Encryption of Sensitive Data
The product does not encrypt sensitive or critical information before storage or transmission.