In ABB IP GATEWAY 3.39 and prior, some configuration files contain passwords stored in plain-text, which may allow an attacker to gain unauthorized access.
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/104388 | vdb entry third party advisory |
https://ics-cert.us-cert.gov/advisories/ICSA-18-156-01 | third party advisory us government resource |