Atlas Copco Power Focus 6000 web server does not sanitize the login information stored by the authenticated user’s browser, which could allow an attacker with access to the user’s computer to gain credential information of the controller.
References
Link | Resource |
---|---|
https://www.cisa.gov/news-events/ics-advisories/icsa-23-159-01 | Third Party Advisory US Government Resource |
Configurations
Configuration 1 (hide)
AND |
|
History
12 Jun 2023, 20:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-06-12 20:15
Updated : 2024-02-04 23:37
NVD link : CVE-2023-1897
Mitre link : CVE-2023-1897
CVE.ORG link : CVE-2023-1897
JSON object : View
Products Affected
atlascopco
- power_focus_6000_firmware
- power_focus_6000
CWE
CWE-312
Cleartext Storage of Sensitive Information