Impact
Credentials for built‑in users are stored in the User directory of PcVue projects without proper protection. A local attacker who can access the system’s filesystem can read these credentials, enabling unauthorized account use and potential escalation. This weakness is an instance of insecure direct storage of passwords, classified as CWE‑256.
Affected Systems
The vulnerability affects all versions of Arcinfo PcVue prior to 17.0.0, including any projects that load User directories from earlier releases. The official fix is to install PcVue 17.0.0 (release 17.0.0902.3726) or newer, which removes the ability to load User directories containing insecure credentials. If existing projects were designed with an earlier version, they must be migrated using the ProjectUtility CLI tool as documented.
Risk and Exploitability
The vulnerability’s CVSS score of 6.8 indicates moderate severity. Because only local access is sufficient to read the stored credentials, the risk is confined to individuals who can physically or otherwise access the control system. The EPSS score is under 1%, reflecting a low but non‑zero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Nonetheless, if an attacker gains local access, they could retrieve credentials and impersonate built‑in users, potentially compromising the system’s integrity.
OpenCVE Enrichment