SB2019061112 - Information disclosure in Siemens SCALANCE X
Published: June 11, 2019 Updated: June 26, 2019
Security Bulletin ID
SB2019061112
Severity
Low
Patch available
NO
Number of vulnerabilities
1
Exploitation vector
Local access
Highest impact
Information disclosure
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Storing passwords in a recoverable format (CVE-ID: CVE-2019-6567)
The vulnerability allows a local attacker to gain passwords to the affected devices.
The vulnerability exists due to the affected devices store passwords in a recoverable format. A local attacker can extract and recover device passwords from the device configuration.
Successful exploitation of this vulnerability requires access to a device configuration backup and impacts confidentiality of the stored passwords.
Remediation
Cybersecurity Help is not aware of any official remediation provided by the vendor.