CVE-2023-22389
Severity CVSS v4.0:
Pending analysis
Type:
CWE-256
Plaintext Storage of a Password
Publication date:
30/01/2023
Last modified:
07/11/2023
Description
<br />
Snap One Wattbox WB-300-IP-3 versions WB10.9a17 and prior store passwords in a plaintext file when the device configuration is exported via Save/Restore–>Backup Settings, which could be read by any user accessing the file. <br />
<br />
<br />
<br />
<br />
Impact
Base Score 3.x
6.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:snapav:wattbox_wb-300-ip-3_firmware:*:*:*:*:*:*:*:* | wb10.9a17 (including) | |
| cpe:2.3:h:snapav:wattbox_wb-300-ip-3:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



