Snap One Wattbox WB-300-IP-3 versions WB10.9a17 and prior store passwords in a plaintext file when the device configuration is exported via Save/Restore–>Backup Settings, which could be read by any user accessing the file.
Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Snap One has released the following updates for the affected products: * Version WB10.B929 https://app.ovrc.com/#/user-settings (login required)
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-26552 | Snap One Wattbox WB-300-IP-3 versions WB10.9a17 and prior store passwords in a plaintext file when the device configuration is exported via Save/Restore–>Backup Settings, which could be read by any user accessing the file. |
| Link | Providers |
|---|---|
| https://www.cisa.gov/uscert/ics/advisories/icsa-23-026-03 |
|
Thu, 16 Jan 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2025-01-16T21:58:34.400Z
Reserved: 2023-01-23T23:57:52.031Z
Link: CVE-2023-22389
Updated: 2024-08-02T10:07:06.559Z
Status : Modified
Published: 2023-01-30T23:15:11.450
Modified: 2024-11-21T07:44:42.877
Link: CVE-2023-22389
No data.
OpenCVE Enrichment
No data.
EUVD