6.8

CVE-2023-43776

Weak encoding vulnerability in easyE4

Eaton easyE4 PLC offers a device password protection functionality to facilitate a secure connection and prevent unauthorized access. It was observed that the device password was stored with a weak encoding algorithm in the easyE4 program file when exported to SD card (*.PRG file ending).
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
EatonEasy-box-e4-ac1 Firmware Version < 2.02
   EatonEasy-box-e4-ac1 Version-
EatonEasy-box-e4-dc1 Firmware Version < 2.02
   EatonEasy-box-e4-dc1 Version-
EatonEasy-box-e4-uc1 Firmware Version < 2.02
   EatonEasy-box-e4-uc1 Version-
EatonEasy-e4-ac-12rc1p Firmware Version < 2.02
   EatonEasy-e4-ac-12rc1p Version-
EatonEasy-e4-ac-12rcx1p Firmware Version < 2.02
   EatonEasy-e4-ac-12rcx1p Version-
EatonEasy-e4-ac-16re1p Firmware Version < 2.02
   EatonEasy-e4-ac-16re1p Version-
EatonEasy E4-ac-8re1p Firmware Version < 2.02
   EatonEasy E4-ac-8re1p Version-
EatonEasy-e4-dc-12tc1p Firmware Version < 2.02
   EatonEasy-e4-dc-12tc1p Version-
EatonEasy-e4-dc-12tcx1p Firmware Version < 2.02
   EatonEasy-e4-dc-12tcx1p Version-
EatonEasy-e4-dc-16te1p Firmware Version < 2.02
   EatonEasy-e4-dc-16te1p Version-
EatonEasy-e4-dc-4pe1p Firmware Version < 2.02
   EatonEasy-e4-dc-4pe1p Version-
EatonEasy-e4-dc-6ae1p Firmware Version < 2.02
   EatonEasy-e4-dc-6ae1p Version-
EatonEasy-e4-dc-8te1p Firmware Version < 2.02
   EatonEasy-e4-dc-8te1p Version-
EatonEasy-e4-uc-12rc1p Firmware Version < 2.02
   EatonEasy-e4-uc-12rc1p Version-
EatonEasy-e4-uc-12rcx1p Firmware Version < 2.02
   EatonEasy-e4-uc-12rcx1p Version-
EatonEasy-e4-uc-16re1 Firmware Version < 2.02
   EatonEasy-e4-uc-16re1 Version-
EatonEasy-e4-uc-16re1p Firmware Version < 2.02
   EatonEasy-e4-uc-16re1p Version-
EatonEasy-e4-uc-8re1p Firmware Version < 2.02
   EatonEasy-e4-uc-8re1p Version-
EatonXv-102-a035tqrb-1e4 Firmware Version < 2.02
   EatonXv-102-a035tqrb-1e4 Version-
EatonXv-102-a3-57tvrb-1e4 Firmware Version < 2.02
   EatonXv-102-a3-57tvrb-1e4 Version-
EatonXv100-box-e4-dc1 Firmware Version < 2.02
   EatonXv100-box-e4-dc1 Version-
EatonXv100-box-e4-uc1 Firmware Version < 2.02
   EatonXv100-box-e4-uc1 Version-
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.12% 0.023
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.6 0.7 5.9
CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CybersecurityCOE@eaton.com 6.8 0.2 6
CVSS:3.1/AV:P/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H
CWE-261 Weak Encoding for Password

Obscuring a password with a trivial encoding does not protect the password.

CWE-326 Inadequate Encryption Strength

The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.

https://www.eaton.com/content/dam/eaton/company/news-insights/cybersecurity/security-bulletins/etn-va-2023-1010.pdf
Vendor Advisory
Mitigation