Exploitation Summary
EIP tracks 1 public exploit for CVE-2019-11369. PoCs published by Luca.Chiou.
AI-analyzed exploit summary This exploit describes an information leakage vulnerability in Carel pCOWeb devices where user passwords are stored in plaintext and accessible via a specific URL. The PoC provides a path to retrieve sensitive credentials without requiring authentication.
Description
An issue was discovered in Carel pCOWeb prior to B1.2.4. In /config/pw_changeusers.html the device stores cleartext passwords, which may allow sensitive information to be read by someone with access to the device.
Exploits (1)
This exploit describes an information leakage vulnerability in Carel pCOWeb devices where user passwords are stored in plaintext and accessible via a specific URL. The PoC provides a path to retrieve sensitive credentials without requiring authentication.
References (3)
Scores
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H