CVE-2022-47561
5.5
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 1.8 / Impact: 3.6
Source: NVD
Description
The web application stores credentials in clear text in the "admin.xml" file, which can be accessed without logging into the website, which could allow an attacker to obtain credentials related to all users, including admin users, in clear text, and use them to subsequently execute malicious actions.
Affected (2)
Products: Ormazabal: Ekorccp Firmware, Ekorrci Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 601j |
| Running on/with | Platform Versions |
|---|---|
Ormazabal Ekorccp | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 601j |
| Running on/with | Platform Versions |
|---|---|
Ormazabal Ekorrci | All versions |
Related CWEs
CWE-256
Plaintext Storage of a Password
Storing a password in plaintext may result in a system compromise.
CWE-522
Insufficiently Protected Credentials
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
References (2)
Source: cve-coordination@incibe.es
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Timeline
No history available yet.