Description
An adjacent attacker without authentication can exploit this vulnerability to retrieve a set of user-privileged credentials. These credentials are present during the firmware upgrade procedure.
Problem types
CWE-319 Cleartext Transmission of Sensitive Information
Product status
5.x (custom)
5.x (custom)
5.x (custom)
5.x (custom)
5.x (custom)
Credits
Diego Giubertoni of Nozomi Networks reported these vulnerabilities to CISA.
References
www.cisa.gov/news-events/ics-advisories/icsa-25-261-06