#VU59903 Unprotected storage of credentials in ICONICS, Inc. products - CVE-2022-23129
Published: January 21, 2022
ICONICS Suite
GENESIS64
Energy AnalytiX
Hyper Historian
MobileHMI
ICONICS, Inc.
Description
The vulnerability allows a local user to gain access to other users' credentials.
The vulnerability exists due to application stored credentials in plain text in a configuration file on the system within the GENESIS64 and MC Works64 Workbench "export to CSV" function. A local administrator can view contents of the configuration file and gain access to passwords for 3rd party integration.