ZeroHour

CVE-2022-47561

CVSS 3.1
5.5 medium
EPSS
<1%p7
Published
()
Modified
Description

The web application stores credentials in clear text in the "admin.xml" file, which can be accessed without logging into the website, which could allow an attacker to obtain credentials related to all users, including admin users, in clear text, and use them to subsequently execute malicious actions.

Vendors
ormazabal
Products
ekorccp firmware, ekorrci firmware
Weakness
CWE-256, CWE-522
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.