Impact
Plaintext passwords are stored in the CONPROSYS nano Series firmware, allowing an attacker who physically reaches the device to read the credentials and compromise access to the remote I/O units. The flaw is a weakness in password storage (CWE-256) that gives direct exposure of secret information.
Affected Systems
All Contec CPSN models are affected, including the Programmable Remote I/O Coupler Unit (Software PLC Type) CPSN-PCB271-S1-041, the Remote I/O Coupler Unit (EtherNet/IP Adapter) CPSN-EOB471EI-[]1, and the Remote I/O Coupler Unit (Server Type) CPSN-MCB271-*. No specific firmware or hardware revision numbers are provided in the advisory.
Risk and Exploitability
The vulnerability received a CVSS 4.1 rating, indicating moderate impact. No EPSS score is available and the issue is not listed in the CISA KEV catalog. Exploitation requires the attacker to have physical access, so the likelihood of remote exploitation is low, but the potential for credential compromise remains if the device is not secured against physical tampering.
OpenCVE Enrichment