8.8

CVE-2019-11369

Exploit
An issue was discovered in Carel pCOWeb prior to B1.2.4. In /config/pw_changeusers.html the device stores cleartext passwords, which may allow sensitive information to be read by someone with access to the device.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
CarelPcoweb Card Firmware Version < b1.2.1
   CarelPcoweb Card Version-
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 7.06% 0.934
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 4 8 2.9
AV:N/AC:L/Au:S/C:P/I:N/A:N
CWE-522 Insufficiently Protected Credentials

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

http://seclists.org/fulldisclosure/2019/Oct/45
https://drive.google.com/open?id=12Sq6oaxe1mC1y71Emo1YladjDjwTdNfb
Third Party Advisory
Exploit
https://github.com/nepenthe0320/cve_poc/blob/master/CVE-2019-11369
Third Party Advisory
Exploit