ZeroHour

CVE-2022-3089

CVSS 3.1
9.8 critical
EPSS
<1%p16
Published
()
Modified
Description

Echelon SmartServer 2.2 with i.LON Vision 2.2 stores cleartext credentials in a file, which could allow an attacker to obtain cleartext usernames and passwords of the SmartServer. If the attacker obtains the file, then the credentials could be used to control the web user interface and file transfer protocol (FTP) server.

Vendors
echelon
Products
i.lon vision
Weakness
CWE-798, CWE-312
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.