The configuration file stores credentials in cleartext. An attacker with local access rights can read or modify the configuration file, potentially resulting in the service being abused due to sensitive information exposure.
https://www.cisa.gov/news-events/ics-advisories/icsa-24-268-05
Published: 2024-09-21
Updated: 2024-09-27
Base Score: 6.2
Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:N
Severity: Medium
Base Score: 7.1
Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Severity: High
Base Score: 6.8
Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Severity: Medium