First published: Sun Jun 11 2023(Updated: )
The Danfoss AK-EM100 stores login credentials in cleartext.
Credit: csirt@divd.nl csirt@divd.nl
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Danfoss AK-EM100 Firmware | ||
Danfoss AK-EM100 Firmware | <2.2.0.12 | |
Danfoss AK-EM100 Firmware | <2.2.0.12 | |
Danfoss AK-EM100 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-22584 is a vulnerability in the Danfoss AK-EM100 that allows an attacker to access login credentials stored in cleartext.
CVE-2023-22584 has a severity level of high with a CVSS score of 7.5.
The Danfoss AK-EM100 firmware versions up to exclusive version 2.2.0.12 are affected by CVE-2023-22584.
To fix CVE-2023-22584, update the Danfoss AK-EM100 firmware to a version above 2.2.0.12 that addresses the vulnerability.
More information about CVE-2023-22584 can be found at the following references: [Link 1](https://csirt.divd.nl/DIVD-2023-00021), [Link 2](https://divd.nl/cves/CVE-2023-22584).