CVE-2023-43776
6.6
Vector
CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 0.7 / Impact: 5.9
Source: NVD
Description
Eaton easyE4 PLC offers a device password protection functionality to facilitate a secure connection and prevent unauthorized access. It was observed that the device password was stored with a weak encoding algorithm in the easyE4 program file when exported to SD card (*.PRG file ending).
Affected (22)
Products: Eaton: Easy Box E4 Ac1 Firmware, Easy Box E4 Dc1 Firmware, Easy Box E4 Uc1 Firmware, Easy E4 Ac 12rc1p Firmware, Easy E4 Ac 12rcx1p Firmware, Easy E4 Ac 16re1p Firmware, Easy E4 Ac 8re1p Firmware, Easy E4 Dc 12tc1p Firmware, Easy E4 Dc 12tcx1p Firmware, Easy E4 Dc 16te1p Firmware, Easy E4 Dc 4pe1p Firmware, Easy E4 Dc 6ae1p Firmware, Easy E4 Dc 8te1p Firmware, Easy E4 Uc 12rc1p Firmware, Easy E4 Uc 12rcx1p Firmware, Easy E4 Uc 16re1 Firmware, Easy E4 Uc 16re1p Firmware, Easy E4 Uc 8re1p Firmware, Xv 102 A035tqrb 1e4 Firmware, Xv 102 A3 57tvrb 1e4 Firmware, Xv100 Box E4 Dc1 Firmware, Xv100 Box E4 Uc1 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.02 |
| Running on/with | Platform Versions |
|---|---|
Eaton Easy Box E4 Ac1 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.02 |
| Running on/with | Platform Versions |
|---|---|
Eaton Easy Box E4 Dc1 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.02 |
| Running on/with | Platform Versions |
|---|---|
Eaton Easy Box E4 Uc1 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.02 |
| Running on/with | Platform Versions |
|---|---|
Eaton Easy E4 Ac 12rc1p | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.02 |
| Running on/with | Platform Versions |
|---|---|
Eaton Easy E4 Ac 12rcx1p | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.02 |
| Running on/with | Platform Versions |
|---|---|
Eaton Easy E4 Ac 16re1p | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.02 |
| Running on/with | Platform Versions |
|---|---|
Eaton Easy E4 Ac 8re1p | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.02 |
| Running on/with | Platform Versions |
|---|---|
Eaton Easy E4 Dc 12tc1p | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.02 |
| Running on/with | Platform Versions |
|---|---|
Eaton Easy E4 Dc 12tcx1p | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.02 |
| Running on/with | Platform Versions |
|---|---|
Eaton Easy E4 Dc 16te1p | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.02 |
| Running on/with | Platform Versions |
|---|---|
Eaton Easy E4 Dc 4pe1p | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.02 |
| Running on/with | Platform Versions |
|---|---|
Eaton Easy E4 Dc 6ae1p | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.02 |
| Running on/with | Platform Versions |
|---|---|
Eaton Easy E4 Dc 8te1p | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.02 |
| Running on/with | Platform Versions |
|---|---|
Eaton Easy E4 Uc 12rc1p | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.02 |
| Running on/with | Platform Versions |
|---|---|
Eaton Easy E4 Uc 12rcx1p | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.02 |
| Running on/with | Platform Versions |
|---|---|
Eaton Easy E4 Uc 16re1 | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.02 |
| Running on/with | Platform Versions |
|---|---|
Eaton Easy E4 Uc 16re1p | All versions |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.02 |
| Running on/with | Platform Versions |
|---|---|
Eaton Easy E4 Uc 8re1p | All versions |
Configuration S
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.02 |
| Running on/with | Platform Versions |
|---|---|
Eaton Xv 102 A035tqrb 1e4 | All versions |
Configuration T
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.02 |
| Running on/with | Platform Versions |
|---|---|
Eaton Xv 102 A3 57tvrb 1e4 | All versions |
Configuration U
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.02 |
| Running on/with | Platform Versions |
|---|---|
Eaton Xv100 Box E4 Dc1 | All versions |
Configuration V
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.02 |
| Running on/with | Platform Versions |
|---|---|
Eaton Xv100 Box E4 Uc1 | All versions |
Related CWEs
CWE-261
Weak Encoding for Password
Obscuring a password with a trivial encoding does not protect the password.
CWE-326
Inadequate Encryption Strength
The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.
References (2)
Source: CybersecurityCOE@eaton.com
MitigationVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationVendor Advisory
Timeline
No history available yet.