Schneider-electric

Easergy Builder

6 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.03%
  • Veröffentlicht 23.07.2020 21:15:12
  • Zuletzt bearbeitet 21.11.2024 05:37:17

A CWE-327: Use of a Broken or Risky Cryptographic Algorithm vulnerability exists in Easergy Builder (Version 1.4.7.2 and older) which could allow an attacker access to the authorization credentials for a device and gain full access.

  • EPSS 0.05%
  • Veröffentlicht 23.07.2020 21:15:12
  • Zuletzt bearbeitet 21.11.2024 05:37:17

A CWE-321: Use of hard-coded cryptographic key stored in cleartext vulnerability exists in Easergy Builder V1.4.7.2 and prior which could allow an attacker to decrypt a password.

  • EPSS 0.03%
  • Veröffentlicht 23.07.2020 21:15:12
  • Zuletzt bearbeitet 21.11.2024 05:37:17

A CWE-316: Cleartext Storage of Sensitive Information in Memory vulnerability exists in Easergy Builder V1.4.7.2 and prior which could allow an attacker access to login credentials.

  • EPSS 0.03%
  • Veröffentlicht 23.07.2020 21:15:12
  • Zuletzt bearbeitet 21.11.2024 05:37:17

A CWE-312: Cleartext Storage of Sensitive Information vulnerability exists in Easergy Builder (Version 1.4.7.2 and older) which could allow an attacker to read user credentials.

  • EPSS 0.24%
  • Veröffentlicht 23.07.2020 21:15:12
  • Zuletzt bearbeitet 21.11.2024 05:37:17

A CWE-20: Improper input validation vulnerability exists in Easergy Builder (Version 1.4.7.2 and older) which could allow an attacker to modify project configuration files.

  • EPSS 0.28%
  • Veröffentlicht 23.07.2020 21:15:12
  • Zuletzt bearbeitet 21.11.2024 05:37:18

A CWE-521: Weak Password Requirements vulnerability exists in Easergy Builder (Version 1.4.7.2 and older) which could allow an attacker to compromise a user account.