Valmet DNA user passwords in plain text. This practice poses a security risk as attackers who gain access to local project data can read the passwords.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-9117 Valmet DNA user passwords in plain text. This practice poses a security risk as attackers who gain access to local project data can read the passwords.
Fixes

Solution

The solution is available from Valmet Automation Customer Service.


Workaround

No workaround given by the vendor.

History

Tue, 01 Apr 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 01 Apr 2025 04:15:00 +0000

Type Values Removed Values Added
Description Valmet DNA user passwords in plain text. This practice poses a security risk as attackers who gain access to local project data can read the passwords.
Title Valmet DNA user passwords in plain text
Weaknesses CWE-312
References
Metrics cvssV4_0

{'score': 5.2, 'vector': 'CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/R:A/V:D/RE:L/U:Green'}


cve-icon MITRE

Status: PUBLISHED

Assigner: NCSC-FI

Published:

Updated: 2025-04-01T14:13:12.389Z

Reserved: 2025-01-13T12:24:48.092Z

Link: CVE-2025-0418

cve-icon Vulnrichment

Updated: 2025-04-01T14:13:09.368Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-04-01T04:15:39.550

Modified: 2025-04-01T20:26:11.547

Link: CVE-2025-0418

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-07-12T15:26:28Z