CVE Vulnerabilities

CVE-2022-2103

Insufficiently Protected Credentials

Published: Jun 24, 2022 | Modified: Jul 05, 2022
CVSS 3.x
9.1
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS 2.x
6.4 MEDIUM
AV:N/AC:L/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

An attacker with weak credentials could access the TCP port via an open FTP port, allowing an attacker to read sensitive files and write to remotely executable directories.

Weakness

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Affected Software

Name Vendor Start Version End Version
Sepcos_control_and_protection_relay_firmware Secheron 1.23.0 (including) 1.23.21 (excluding)
Sepcos_control_and_protection_relay_firmware Secheron 1.24.0 (including) 1.24.8 (excluding)
Sepcos_control_and_protection_relay_firmware Secheron 1.25.0 (including) 1.25.3 (excluding)

Potential Mitigations

References