#VU59294 Unprotected storage of credentials in IDEC Corporation products - CVE-2021-37401
Published: January 7, 2022
FC6A MICROSmart All-in-One CPU Module
FC6B MICROSmart All-in-One CPU Module
FC6A MICROSmart Plus CPU Module
FC6B MICROSmart Plus CPU Module
FT1A Controller SmartAXIS Pro/Lite
WindLDR
WindEDIT Lite
Data File Manager
WindEDIT
IDEC Corporation
Description
The vulnerability allows a remote attacker to gain access to other users' credentials.
The vulnerability exists due to application stored credentials in plain text in a configuration file on the system. A remote attacker on the local network can view contents of the configuration file and gain access to passwords for 3rd party integration.