#VU71605 Unprotected storage of credentials in Wattbox WB-300-IP-3 - CVE-2023-22389
Published: January 27, 2023
Wattbox WB-300-IP-3
Snap One
Description
The vulnerability allows a remote attacker to gain access to other users' credentials.
The vulnerability exists due to application stored credentials in plain text in a configuration file on the system. A remote attacker on the local network can view contents of the configuration file and gain access to passwords for 3rd party integration.