Use of Hard-coded Cryptographic Key in EcoStruxure Operator Terminal Expert - #VU47730

 

Use of Hard-coded Cryptographic Key in EcoStruxure Operator Terminal Expert - #VU47730

Published: October 20, 2020


Vulnerability identifier: #VU47730
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-321
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information on the target system.

The vulnerability exists due to presence of a hard-coded cryptographic key in the default configuration file. A remote attacker can decrypt the sensitive data on the target system.


Affected software

EcoStruxure Operator Terminal Expert

Remediation

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.


External References

Related Security Bulletins