The Campbell Scientific CSI Web Server stores web authentication credentials in a file with a specific file name. Passwords within that file are stored in a weakly encoded format. There is no known way to remotely access the file unless it has been manually renamed. However, if an attacker were to gain access to the file, passwords could be decoded and reused to gain access.
CVSS

No CVSS.

History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: icscert

Published: 2024-05-28T18:43:07.150Z

Updated: 2024-06-04T18:02:06.311Z

Reserved: 2024-05-28T13:59:14.696Z


Link: CVE-2024-5434

JSON object: View

cve-icon NVD Information

Status : Awaiting Analysis

Published: 2024-05-28T19:15:11.623

Modified: 2024-05-29T13:02:09.280


Link: CVE-2024-5434

JSON object: View

cve-icon Redhat Information

No data.

CWE