CVE-2022-47561
Summary
| CVE | CVE-2022-47561 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-09-20 08:15:00 UTC |
| Updated | 2023-11-07 03:56:00 UTC |
| Description | ** UNSUPPPORTED WHEN ASSIGNED ** The web application stores credentials in clear text in the "admin.xml" file, which can be accessed without logging into the website, which could allow an attacker to obtain credentials related to all users, including admin users, in clear text, and use them to subsequently execute malicious actions. |
Risk And Classification
Problem Types: CWE-522
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Ormazabal | Ekorccp | - | All | All | All |
| Operating System | Ormazabal | Ekorccp Firmware | 601j | All | All | All |
| Hardware | Ormazabal | Ekorrci | - | All | All | All |
| Operating System | Ormazabal | Ekorrci Firmware | 601j | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Multiple Vulnerabilities Ormazabal Products | INCIBE-CERT | INCIBE | MISC | www.incibe.es | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.