[Japanese] | |
JVNDB-2024-000089 | |
WindLDR and WindO/I-NV4 store sensitive information in cleartext | |
Overview | |
PLC programming software "WindLDR" and Operator Interfaces' Touchscreen Programming Software "WindO/I-NV4" provided by IDEC Corporation store sensitive information in cleartext form (CWE-312). | |
CVSS Severity (What is CVSS?) | |
CVSS V3 Severity:
Base Metrics 5.9 (Medium) [IPA Score]
[Comment]
Confidentiality(C) impact is accessed as primary, and Integrity(I) and Availability(A) impacts are assessed as secondary.
| |
Affected Products | |
| |
IDEC Corporation | |
| |
Impact | |
An attacker who obtained the product's project file may obtain user credentials of the PLC or Operator Interfaces. As a result, an attacker may be able to manipulate and/or suspend the PLC and Operator Interfaces by accessing or hijacking them. | |
Solution | |
[Update the Software] | |
Vendor Information | |
IDEC Corporation | |
CWE (What is CWE?) | |
| |
CVE (What is CVE?) | |
| |
References | |
| |
Revision History | |
|
Date Public | 2024/08/29 |
Date First Published | 2024/08/29 |
Date Last Updated | 2024/09/24 |