A CWE-311: Missing Encryption of Sensitive Data vulnerability exists that could allow authentication credentials to be recovered when an attacker breaks the encoding. Affected Products: Wiser Smart, EER21000 & EER21001 (V4.5 and prior)
The product does not encrypt sensitive or critical information before storage or transmission.
Link | Tags |
---|---|
https://www.se.com/ww/en/download/document/SEVD-2022-130-03/ | mitigation vendor advisory |