SaTECH BCU, in its firmware version 2.1.3, performs weak password encryption. This allows an attacker with access to the device's system or website to obtain the credentials, as the storage methods used are not strong enough in terms of encryption.
Metrics
Affected Vendors & Products
References
History
Fri, 28 Mar 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 28 Mar 2025 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SaTECH BCU, in its firmware version 2.1.3, performs weak password encryption. This allows an attacker with access to the device's system or website to obtain the credentials, as the storage methods used are not strong enough in terms of encryption. | |
| Title | Weak Encoding for Password vulnerability in saTECH BCU | |
| Weaknesses | CWE-261 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: INCIBE
Published: 2025-03-28T13:15:08.022Z
Updated: 2025-03-28T13:34:42.132Z
Reserved: 2025-03-27T10:59:43.270Z
Link: CVE-2025-2862
Updated: 2025-03-28T13:34:38.341Z
Status : Awaiting Analysis
Published: 2025-03-28T14:15:21.257
Modified: 2025-03-28T18:11:40.180
Link: CVE-2025-2862
No data.