Econolite EOS versions prior to 3.2.23 lack a password requirement for gaining “READONLY” access to log files and certain database and configuration files. One such file contains tables with MD5 hashes and usernames for all defined users in the control software, including administrators and technicians.
References
Link Resource
https://www.cisa.gov/uscert/ics/advisories/icsa-23-026-02 Third Party Advisory US Government Resource
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: icscert

Published: 2023-01-26T20:37:53.380Z

Updated: 2023-06-20T15:37:19.367Z

Reserved: 2023-01-23T18:19:27.265Z


Link: CVE-2023-0451

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2023-01-26T21:18:08.673

Modified: 2023-06-20T16:15:09.660


Link: CVE-2023-0451

JSON object: View

cve-icon Redhat Information

No data.