#VU17074 Information disclosure in PNOZmulti Configurator - CVE-2018-19009
Published: January 10, 2019 / Updated: January 18, 2019
PNOZmulti Configurator
Pilz
Description
The vulnerability allows a local authenticated attacker to obtain potentially sensitive information.
The vulnerability exists on the PMI m107 diag HMI device due to cleartext storage of sensitive information. A local attacker can view sensitive credential data in clear-text. An attacker with access to this sensitive data and physical access to the PMI m107 diag can modify data on the HMI device.