Home
MEDIUM: 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NDefault status
unaffected
1.0 (custom) before 9.0
affected
Default status
unaffected
1.0 (custom) before 9.0
affected
Default status
unaffected
1.0 (custom) before 9.0
affected
Description
Insufficient encryption strength in Sprecher Automation SPRECON-E-C, SPRECON-E-P, and SPRECON-E-T3 allows a local unprivileged attacker to extract data from update images and thus obtain limited information about the architecture and internal processes.
Problem types
CWE-326 Inadequate Encryption Strength
Product status
1.0 (custom) before 9.0
1.0 (custom) before 9.0
1.0 (custom) before 9.0
Credits
Sec-Consult Security Labs
References
www.sprecher-automation.com/...curity/PDF/SPR-2511043_de.pdf