A CWE-311: Missing Encryption of Sensitive Data vulnerability exists in Easergy T300 (firmware 2.7 and older), that would allow an attacker to read network traffic over HTTP protocol.
The product does not encrypt sensitive or critical information before storage or transmission.
Link | Tags |
---|---|
https://www.se.com/ww/en/download/document/SEVD-2020-315-06/ | vendor advisory |
https://us-cert.cisa.gov/ics/advisories/icsa-20-343-03 | third party advisory us government resource |