First published: Wed Jun 12 2019(Updated: )
Fuji Electric V-Server before 6.0.33.0 stores database credentials in project files as plaintext. An attacker that can gain access to the project file can recover the database credentials and gain access to the database server.
Credit: vulnreport@tenable.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fujielectric V-server | <6.0.33.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-3947 is a vulnerability in Fuji Electric V-Server before version 6.0.33.0 that stores database credentials in project files as plaintext.
CVE-2019-3947 has a severity rating of 9.8, which is considered critical.
CVE-2019-3947 allows an attacker who gains access to the project file to recover the database credentials stored in plaintext and gain access to the database server.
To fix CVE-2019-3947, it is recommended to upgrade to Fuji Electric V-Server version 6.0.33.0 or later, where the issue is patched.
Yes, you can find more information about CVE-2019-3947 at the following references: [SecurityFocus](http://www.securityfocus.com/bid/108740) and [Tenable Research](https://www.tenable.com/security/research/tra-2019-27).