漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Rockwell Automation ISaGRAF5 Runtime Unprotected Storage of Credentials
Vulnerability Description
Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x stores the password in plaintext in a file that is in the same directory as the executable file. ISaGRAF Runtime reads the file and saves the data in a variable without any additional modification. A local, unauthenticated attacker could compromise the user passwords, resulting in information disclosure.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
明文存储口令
Vulnerability Title
Rockwell Automation ISaGRAF 安全漏洞
Vulnerability Description
Rockwell Automation ISaGRAF是美国罗克韦尔(Rockwell Automation)公司的一种用于创建集成自动化解决方案的自动化软件技术。它设计为可扩展和便携,适合开发小型控制器和大型分布式自动化系统。 Rockwell Automation ISaGRAF 存在安全漏洞,该漏洞源于将密码明文存储在与可执行文件在同一目录下的文件中。未经认证的攻击者可利用该漏洞可以破坏用户的密码,导致信息泄露。
CVSS Information
N/A
Vulnerability Type
N/A