Kastle Systems firmware prior to May 1, 2024, stored machine credentials in cleartext, which may allow an attacker to access sensitive information.
Solution:
The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.
Link | Tags |
---|---|
https://www.cisa.gov/news-events/ics-advisories/icsa-24-263-05 | us government resource government resource third party advisory |