A local, low-privileged attacker can learn the password of the connected controller in PLC Designer V4 due to an incorrect implementation that results in the password being displayed in plain text under special conditions.
References
Link | Resource |
---|---|
https://certvde.com/en/advisories/VDE-2025-043/ |
Configurations
No configuration.
History
26 Jun 2025, 18:57
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
25 Jun 2025, 10:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-06-25 10:15
Updated : 2025-06-26 18:57
NVD link : CVE-2025-41647
Mitre link : CVE-2025-41647
CVE.ORG link : CVE-2025-41647
JSON object : View
Products Affected
No product.
CWE
CWE-312
Cleartext Storage of Sensitive Information