CVE-2019-3947
CRITICALFuji Electric V-Server < 6.0.33.0 - Plaintext Database Credential Exposure in Project Files
Title source: llmDescription
Fuji Electric V-Server before 6.0.33.0 stores database credentials in project files as plaintext. An attacker that can gain access to the project file can recover the database credentials and gain access to the database server.
References (2)
Core 2
Core References
Exploit, Third Party Advisory x_refsource_misc
https://www.tenable.com/security/research/tra-2019-27
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/108740
Scores
CVSS v3
9.8
EPSS
0.0158
EPSS Percentile
72.4%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-522
Status
published
Products (1)
fujielectric/v-server
< 6.0.33.0
Published
Jun 12, 2019
Tracked Since
Feb 18, 2026