vendor:
Solar-Log 500
by:
Luca.Chiou
7.5
CVSS
HIGH
Unprotected Storage of Credentials
256
CWE
Product Name: Solar-Log 500
Affected Version From: Solar-Log 500 all versions prior to 2.8.2 Build 52 - 23.04.2013
Affected Version To: Solar-Log 500 all versions prior to 2.8.2 Build 52 - 23.04.2013
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Proprietary devices
2021
Solar-Log 500 2.8.2 – Unprotected Storage of Credentials
An issue was discovered in Solar-Log 500 prior to 2.8.2 Build 52 - 23.04.2013. In /export.html, email.html, sms.html, the devices store plaintext passwords, which may allow sensitive information to be read by someone with access to the device. Proof of Concept: Browse the configuration page in Solar-Log 500, we can find out that the passwords of FTP, SMTP, SMS services are stored in plaintext.
Mitigation:
Ensure that passwords are stored in an encrypted format and not in plaintext.