SB2022113007 - Cleartext storage of sensitive information in Hitachi Energy IED Connectivity Packages and PCM600 Products
Published: November 30, 2022
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Cleartext storage of sensitive information (CVE-ID: CVE-2022-2513)
The vulnerability allows a local attacker to gain access to potentially sensitive information.
The vulnerability exists due to user credentials are stored in plaintext in the database within the Intelligent Electronic Device (IED) Connectivity Package (ConnPack) credential storage function. A local attacker can obtain IED credentials.
Remediation
Install update from vendor's website.