#VU22294 Unprotected storage of credentials in pCOWeb - CVE-2019-11369
Published: October 25, 2019
pCOWeb
Carel
Description
The vulnerability allows a remote user to gain access to other users' credentials.
The vulnerability exists due to application stored credentials in plain text in "/config/pw_changeusers.html" file on the system. A remote authenticated user can view contents of the configuration file and gain access to passwords for 3rd party integration.