PT-2022-7913 · Unknown · Sicunet Access Controller
CVSS v3.1
5.9
Medium
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
SICUNET Access Controller version 0.32-05z
Description
A vulnerability was found in the Password Storage component, leading to weak encryption. The manipulation requires a local attack.
Recommendations
For SICUNET Access Controller version 0.32-05z, consider updating the password storage mechanism to use stronger encryption algorithms to mitigate the risk of weak encryption. As a temporary workaround, restrict local access to minimize the risk of exploitation.
Fix
Cleartext Storage of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sicunet Access Controller