Unprotected storage of credentials in IDEC Corporation products - CVE-2021-37401
Published: January 7, 2022
Vulnerability details
The vulnerability allows a remote attacker to gain access to other users' credentials.
The vulnerability exists due to application stored credentials in plain text in a configuration file on the system. A remote attacker on the local network can view contents of the configuration file and gain access to passwords for 3rd party integration.
Affected software
WindEDIT
FC6A MICROSmart Plus CPU Module
FC6B MICROSmart Plus CPU Module
FT1A Controller SmartAXIS Pro/Lite
FC6A MICROSmart All-in-One CPU Module
WindLDR
Data File Manager
WindEDIT Lite
How to mitigate CVE-2021-37401
FC6A MICROSmart Plus CPU Module - update to 2.40
FC6B MICROSmart Plus CPU Module - update to 2.40
FT1A Controller SmartAXIS Pro/Lite - update to 2.40
FC6A MICROSmart All-in-One CPU Module - update to 2.40
WindLDR - update to 8.20.0
Data File Manager - update to 2.13.0
WindEDIT Lite - update to 1.4.0