CVE Published: 26/01/2023 |
CVE Updated: 02/08/2024 |
CVE Year: 2023 Source: icscert |
Vendor: Econolite |
Product: EOS Status : PUBLISHED
CVE-2023-0451 Description
Econolite EOS versions prior to 3.2.23 lack a password
requirement for gaining “READONLY” access to log files and certain database and
configuration files. One such file contains tables with MD5 hashes and
usernames for all defined users in the control software, including
administrators and technicians.
Metrics
CVSS Version: 3.1 |
Base Score: 7.5 HIGH Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N