CVE-2023-22584: Cleartext credentials in Danfoss AK-EM100
Published Jun 11, 2023
·Updated
The Danfoss AK-EM100 stores login credentials in cleartext.
Affected Software
4 affected components
All of the following
Danfoss AK-EM100
Danfoss Ak-em100 Firmware<2.2.0.12
Danfoss Ak-em100 Firmware<2.2.0.12
Danfoss AK-EM100
Event History
Jun 11, 2023
CVE Published
via MITRE·01:17 PM
Data Sourced
via MITRE·01:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2023-22584?
CVE-2023-22584 is a vulnerability in the Danfoss AK-EM100 that allows an attacker to access login credentials stored in cleartext.
2
How severe is CVE-2023-22584?
CVE-2023-22584 has a severity level of high with a CVSS score of 7.5.
3
What software versions are affected by CVE-2023-22584?
The Danfoss AK-EM100 firmware versions up to exclusive version 2.2.0.12 are affected by CVE-2023-22584.
4
How can I fix CVE-2023-22584?
To fix CVE-2023-22584, update the Danfoss AK-EM100 firmware to a version above 2.2.0.12 that addresses the vulnerability.
5
Where can I find more information about CVE-2023-22584?
More information about CVE-2023-22584 can be found at the following references: [Link 1](https://csirt.divd.nl/DIVD-2023-00021), [Link 2](https://divd.nl/cves/CVE-2023-22584).