Description
Eaton easyE4 PLC offers a device password protection functionality to facilitate a secure connection and prevent unauthorized access. It was observed that the device password was stored with a weak encoding algorithm in the easyE4 program file when exported to SD card (*.PRG file ending).
Published: 2023-10-17
Score: 6.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-48153 Eaton easyE4 PLC offers a device password protection functionality to facilitate a secure connection and prevent unauthorized access. It was observed that the device password was stored with a weak encoding algorithm in the easyE4 program file when exported to SD card (*.PRG file ending).
History

No history.

Subscriptions

Eaton Easy-box-e4-ac1 Easy-box-e4-ac1 Firmware Easy-box-e4-dc1 Easy-box-e4-dc1 Firmware Easy-box-e4-uc1 Easy-box-e4-uc1 Firmware Easy-e4-ac-12rc1p Easy-e4-ac-12rc1p Firmware Easy-e4-ac-12rcx1p Easy-e4-ac-12rcx1p Firmware Easy-e4-ac-16re1p Easy-e4-ac-16re1p Firmware Easy-e4-dc-12tc1p Easy-e4-dc-12tc1p Firmware Easy-e4-dc-12tcx1p Easy-e4-dc-12tcx1p Firmware Easy-e4-dc-16te1p Easy-e4-dc-16te1p Firmware Easy-e4-dc-4pe1p Easy-e4-dc-4pe1p Firmware Easy-e4-dc-6ae1p Easy-e4-dc-6ae1p Firmware Easy-e4-dc-8te1p Easy-e4-dc-8te1p Firmware Easy-e4-uc-12rc1p Easy-e4-uc-12rc1p Firmware Easy-e4-uc-12rcx1p Easy-e4-uc-12rcx1p Firmware Easy-e4-uc-16re1 Easy-e4-uc-16re1 Firmware Easy-e4-uc-16re1p Easy-e4-uc-16re1p Firmware Easy-e4-uc-8re1p Easy-e4-uc-8re1p Firmware Easy E4-ac-8re1p Easy E4-ac-8re1p Firmware Xv-102-a035tqrb-1e4 Xv-102-a035tqrb-1e4 Firmware Xv-102-a3-57tvrb-1e4 Xv-102-a3-57tvrb-1e4 Firmware Xv100-box-e4-dc1 Xv100-box-e4-dc1 Firmware Xv100-box-e4-uc1 Xv100-box-e4-uc1 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: Eaton

Published:

Updated: 2024-09-13T16:27:22.502Z

Reserved: 2023-09-22T05:10:55.258Z

Link: CVE-2023-43776

cve-icon Vulnrichment

Updated: 2024-08-02T19:52:11.035Z

cve-icon NVD

Status : Modified

Published: 2023-10-17T13:15:11.750

Modified: 2024-11-21T08:24:45.880

Link: CVE-2023-43776

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses