Description
Emerson OpenBSI through 2022-04-29 mishandles credential storage. It is an engineering environment for the ControlWave and Bristol Babcock line of RTUs. This environment provides access control functionality through user authentication and privilege management. The credentials for various users are stored insecurely in the SecUsers.ini file by using a simple string transformation rather than a cryptographic mechanism.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-03T06:33:43.165Z
Reserved: 2022-04-29T00:00:00.000Z
Link: CVE-2022-29959
No data.
Status : Modified
Published: 2022-08-16T13:15:09.100
Modified: 2024-11-21T07:00:03.870
Link: CVE-2022-29959
No data.
OpenCVE Enrichment
No data.
Weaknesses