SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-2078

An authorized attacker could access these stored plaintext credentials and gain access to the ftp service.

MEDIUM 6.5EPSS 0.75%

Does this matter?

Lower severity and a low EPSS score (0.75%). Track it; it rarely justifies an emergency change on its own.

Description

Passwords are stored in plain text within the configuration of SICK Package Analytics software up to and including V04.1.1. An authorized attacker could access these stored plaintext credentials and gain access to the ftp service. Storing a password in plaintext allows attackers to easily gain access to systems, potentially compromising personal information or other sensitive information.

CVSS 3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS
0.75% probability · 53th percentile
CISA KEV
Not listed
Weakness
CWE-522
Affected
sick/package analytics
Source
psirt@sick.de

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.