PT-2012-3707 · Wellintech · Kingscada
CVE-2012-1977
·
Publicado
2012-05-09
·
Atualizado
2025-06-26
CVSS v2.0
7.1
Alta
| Vetor | AV:N/AC:M/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
WellinTech KingSCADA version 3.0
Description
The issue concerns the storage of passwords in a cleartext base64 format within the user.db file, allowing attackers to obtain sensitive information by reading this file.
Recommendations
For WellinTech KingSCADA version 3.0, consider encrypting the passwords stored in the user.db file to prevent unauthorized access to sensitive information. As a temporary workaround, restrict access to the user.db file to minimize the risk of exploitation.
Correção
Missing Encryption of Sensitive Data
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Kingscada