CVE-2023-1897

CRITICAL

Atlas Copco Power Focus 6000 - Info Disclosure

Title source: llm
STIX 2.1

Description

Atlas Copco Power Focus 6000 web server does not sanitize the login information stored by the authenticated user’s browser, which could allow an attacker with access to the user’s computer to gain credential information of the controller.

References (1)

Core 1
Core References
Third Party Advisory, US Government Resource
https://www.cisa.gov/news-events/ics-advisories/icsa-23-159-01

Scores

CVSS v3 9.4
EPSS 0.0034
EPSS Percentile 25.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-312
Status published
Products (1)
atlascopco/power_focus_6000_firmware
Published Jun 12, 2023
Tracked Since Feb 18, 2026