Circontrol CirCarLife all versions prior to 4.3.1, the PAP credentials of the device are stored in clear text in a log file that is accessible without authentication.
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
The product writes sensitive information to a log file.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/105816 | third party advisory vdb entry |
https://ics-cert.us-cert.gov/advisories/ICSA-18-305-03 | third party advisory us government resource |