7.5

CVE-2021-3252

Exploit
KACO New Energy XP100U Up to XP-JAVA 2.0 is affected by incorrect access control. Credentials will always be returned in plain-text from the local server during the KACO XP100U authentication process, regardless of whatever passwords have been provided, which leads to an information disclosure vulnerability.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Kaco-newenergyXp100u Firmware Versionxp-java_2.0
   Kaco-newenergyXp100u Version-
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.59% 0.832
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-522 Insufficiently Protected Credentials

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

https://tiger-team-1337.blogspot.com/2021/01/kaco-xp100u-hmi-credential-leak.html
Third Party Advisory
Exploit
Technical Description
https://twitter.com/Kevin2600/status/1351189347501023238
Third Party Advisory
https://us-cert.cisa.gov/ics/alerts/ICS-ALERT-15-224-01
Third Party Advisory
US Government Resource