CVE-2022-27179
MEDIUMRedlion Da50n Firmware - Insufficiently Protected Credentials
Title source: ruleDescription
A malicious actor having access to the exported configuration file may obtain the stored credentials and thereby gain access to the protected resource. If the same passwords were used for other resources, further such assets may be compromised.
Scores
CVSS v3
4.6
EPSS
0.0017
EPSS Percentile
38.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L
Classification
CWE
CWE-522
Status
published
Affected Products (1)
redlion/da50n_firmware
Timeline
Published
Apr 20, 2022
Tracked Since
Feb 18, 2026