CVE Vulnerabilities

CVE-2024-34542

Weak Encoding for Password

Published: Sep 27, 2024 | Modified: Oct 07, 2024
CVSS 3.x
5.7
MEDIUM
Source:
NVD
CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Advantech ADAM-5630 shares user credentials plain text between the device and the user source device during the login process.

Weakness

Obscuring a password with a trivial encoding does not protect the password.

Affected Software

Name Vendor Start Version End Version
Adam-5630_firmware Advantech * 2.5.2 (excluding)

Potential Mitigations

References