Use of Hard-coded Cryptographic Key in EcoStruxure Operator Terminal Expert - #VU47730
Published: October 20, 2020
Vulnerability identifier: #VU47730
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-321
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information on the target system.
The vulnerability exists due to presence of a hard-coded cryptographic key in the default configuration file. A remote attacker can decrypt the sensitive data on the target system.
Affected software
EcoStruxure Operator Terminal Expert
Remediation
Cybersecurity Help is currently unaware of any official solution to address this vulnerability.