Emerson OpenBSI through 2022-04-29 mishandles credential storage. It is an engineering environment for the ControlWave and Bristol Babcock line of RTUs. This environment provides access control functionality through user authentication and privilege management. The credentials for various users are stored insecurely in the SecUsers.ini file by using a simple string transformation rather than a cryptographic mechanism.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2022-08-16T12:23:42
Updated: 2024-08-03T06:33:43.165Z
Reserved: 2022-04-29T00:00:00
Link: CVE-2022-29959
Vulnrichment
No data.
NVD
Status : Modified
Published: 2022-08-16T13:15:09.100
Modified: 2024-11-21T07:00:03.870
Link: CVE-2022-29959
Redhat
No data.