CVE-2022-3089

MEDIUM

Echelon SmartServer 2.2 - Info Disclosure

Title source: llm
STIX 2.1

Description

Echelon SmartServer 2.2 with i.LON Vision 2.2 stores cleartext credentials in a file, which could allow an attacker to obtain cleartext usernames and passwords of the SmartServer. If the attacker obtains the file, then the credentials could be used to control the web user interface and file transfer protocol (FTP) server.

References (1)

Core 1

Scores

CVSS v3 6.3
EPSS 0.0025
EPSS Percentile 16.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-312 CWE-798
Status published
Products (1)
echelon/i.lon_vision 2.2
Published Feb 13, 2023
Tracked Since Feb 18, 2026