Impact
The vulnerability in rust‑iot‑platform allows storage of user passwords in cleartext within the user model. Attackers who can access API responses from user retrieval and listing endpoints are able to directly read these passwords, compromising credential confidentiality. This weakness is identified as CWE‑256, a cleartext storage of sensitive data issue.
Affected Systems
The affected product is rust‑iot‑platform from iot‑ecology. Version information is not specified, so all releases of this product could be impacted until a patch is released.
Risk and Exploitability
The CVSS score of 8.7 classifies this flaw as critical in severity. The EPSS score is not available, indicating no quantitative exploit probability estimate. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is remote: an adversary with network access to the API endpoints could request user data and extract the plaintext passwords. No additional conditions such as privileges specified, suggesting that any user with API access, and potentially unauthenticated traffic, could exploit the flaw.
OpenCVE Enrichment