CVE-2020-11918

MEDIUM

Siime Eye 14.1.00000001.3.330.0.0.3.14 - Cleartext Storage of Sensitive Information in Backup Files

Title source: llm
STIX 2.1

Description

An issue was discovered in Siime Eye 14.1.00000001.3.330.0.0.3.14. When a backup file is created through the web interface, information on all users, including passwords, can be found in cleartext in the backup file. An attacker capable of accessing the web interface can create the backup file.

References (2)

Core 2
Core References
Exploit, Mailing List, Third Party Advisory mailing-list
https://seclists.org/fulldisclosure/2024/Jul/14

Scores

CVSS v3 5.4
EPSS 0.0028
EPSS Percentile 19.5%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-312
Status published
Products (1)
svakom/svakom_siime_eye_firmware 14.1.00000001.3.330.0.0.3.14
Published Nov 07, 2024
Tracked Since Feb 18, 2026