// For flags

CVE-2023-43776

Weak encoding vulnerability in easyE4

Severity Score

6.6
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

Track*
*SSVC
Descriptions

Eaton easyE4 PLC offers a device password protection functionality to facilitate a secure connection and prevent unauthorized access. It was observed that the device password was stored with a weak encoding algorithm in the easyE4 program file when exported to SD card (*.PRG file ending).

Eaton easyE4 PLC ofrece una funcionalidad de protección con contraseña del dispositivo para facilitar una conexión segura y evitar el acceso no autorizado. Se observó que la contraseña del dispositivo se almacenó con un algoritmo de codificación débil en el archivo del programa easyE4 cuando se exportó a la tarjeta SD (final de archivo *.PRG).

*Credits: Manuel Stotz (SySS GmbH)
CVSS Scores
Attack Vector
Physical
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Physical
Attack Complexity
High
Privileges Required
High
User Interaction
Required
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High
* Common Vulnerability Scoring System
SSVC
  • Decision:Track*
Exploitation
None
Automatable
No
Tech. Impact
Total
* Organization's Worst-case Scenario
Timeline
  • 2023-09-22 CVE Reserved
  • 2023-10-17 CVE Published
  • 2024-09-13 CVE Updated
  • 2024-11-18 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-261: Weak Encoding for Password
  • CWE-326: Inadequate Encryption Strength
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Eaton
Search vendor "Eaton"
Easy-box-e4-ac1 Firmware
Search vendor "Eaton" for product "Easy-box-e4-ac1 Firmware"
< 2.02
Search vendor "Eaton" for product "Easy-box-e4-ac1 Firmware" and version " < 2.02"
-
Affected
in Eaton
Search vendor "Eaton"
Easy-box-e4-ac1
Search vendor "Eaton" for product "Easy-box-e4-ac1"
--
Safe
Eaton
Search vendor "Eaton"
Easy-box-e4-dc1 Firmware
Search vendor "Eaton" for product "Easy-box-e4-dc1 Firmware"
< 2.02
Search vendor "Eaton" for product "Easy-box-e4-dc1 Firmware" and version " < 2.02"
-
Affected
in Eaton
Search vendor "Eaton"
Easy-box-e4-dc1
Search vendor "Eaton" for product "Easy-box-e4-dc1"
--
Safe
Eaton
Search vendor "Eaton"
Easy-box-e4-uc1 Firmware
Search vendor "Eaton" for product "Easy-box-e4-uc1 Firmware"
< 2.02
Search vendor "Eaton" for product "Easy-box-e4-uc1 Firmware" and version " < 2.02"
-
Affected
in Eaton
Search vendor "Eaton"
Easy-box-e4-uc1
Search vendor "Eaton" for product "Easy-box-e4-uc1"
--
Safe
Eaton
Search vendor "Eaton"
Easy-e4-ac-12rc1p Firmware
Search vendor "Eaton" for product "Easy-e4-ac-12rc1p Firmware"
< 2.02
Search vendor "Eaton" for product "Easy-e4-ac-12rc1p Firmware" and version " < 2.02"
-
Affected
in Eaton
Search vendor "Eaton"
Easy-e4-ac-12rc1p
Search vendor "Eaton" for product "Easy-e4-ac-12rc1p"
--
Safe
Eaton
Search vendor "Eaton"
Easy-e4-ac-12rcx1p Firmware
Search vendor "Eaton" for product "Easy-e4-ac-12rcx1p Firmware"
< 2.02
Search vendor "Eaton" for product "Easy-e4-ac-12rcx1p Firmware" and version " < 2.02"
-
Affected
in Eaton
Search vendor "Eaton"
Easy-e4-ac-12rcx1p
Search vendor "Eaton" for product "Easy-e4-ac-12rcx1p"
--
Safe
Eaton
Search vendor "Eaton"
Easy-e4-ac-16re1p Firmware
Search vendor "Eaton" for product "Easy-e4-ac-16re1p Firmware"
< 2.02
Search vendor "Eaton" for product "Easy-e4-ac-16re1p Firmware" and version " < 2.02"
-
Affected
in Eaton
Search vendor "Eaton"
Easy-e4-ac-16re1p
Search vendor "Eaton" for product "Easy-e4-ac-16re1p"
--
Safe
Eaton
Search vendor "Eaton"
Easy E4-ac-8re1p Firmware
Search vendor "Eaton" for product "Easy E4-ac-8re1p Firmware"
< 2.02
Search vendor "Eaton" for product "Easy E4-ac-8re1p Firmware" and version " < 2.02"
-
Affected
in Eaton
Search vendor "Eaton"
Easy E4-ac-8re1p
Search vendor "Eaton" for product "Easy E4-ac-8re1p"
--
Safe
Eaton
Search vendor "Eaton"
Easy-e4-dc-12tc1p Firmware
Search vendor "Eaton" for product "Easy-e4-dc-12tc1p Firmware"
< 2.02
Search vendor "Eaton" for product "Easy-e4-dc-12tc1p Firmware" and version " < 2.02"
-
Affected
in Eaton
Search vendor "Eaton"
Easy-e4-dc-12tc1p
Search vendor "Eaton" for product "Easy-e4-dc-12tc1p"
--
Safe
Eaton
Search vendor "Eaton"
Easy-e4-dc-12tcx1p Firmware
Search vendor "Eaton" for product "Easy-e4-dc-12tcx1p Firmware"
< 2.02
Search vendor "Eaton" for product "Easy-e4-dc-12tcx1p Firmware" and version " < 2.02"
-
Affected
in Eaton
Search vendor "Eaton"
Easy-e4-dc-12tcx1p
Search vendor "Eaton" for product "Easy-e4-dc-12tcx1p"
--
Safe
Eaton
Search vendor "Eaton"
Easy-e4-dc-16te1p Firmware
Search vendor "Eaton" for product "Easy-e4-dc-16te1p Firmware"
< 2.02
Search vendor "Eaton" for product "Easy-e4-dc-16te1p Firmware" and version " < 2.02"
-
Affected
in Eaton
Search vendor "Eaton"
Easy-e4-dc-16te1p
Search vendor "Eaton" for product "Easy-e4-dc-16te1p"
--
Safe
Eaton
Search vendor "Eaton"
Easy-e4-dc-4pe1p Firmware
Search vendor "Eaton" for product "Easy-e4-dc-4pe1p Firmware"
< 2.02
Search vendor "Eaton" for product "Easy-e4-dc-4pe1p Firmware" and version " < 2.02"
-
Affected
in Eaton
Search vendor "Eaton"
Easy-e4-dc-4pe1p
Search vendor "Eaton" for product "Easy-e4-dc-4pe1p"
--
Safe
Eaton
Search vendor "Eaton"
Easy-e4-dc-6ae1p Firmware
Search vendor "Eaton" for product "Easy-e4-dc-6ae1p Firmware"
< 2.02
Search vendor "Eaton" for product "Easy-e4-dc-6ae1p Firmware" and version " < 2.02"
-
Affected
in Eaton
Search vendor "Eaton"
Easy-e4-dc-6ae1p
Search vendor "Eaton" for product "Easy-e4-dc-6ae1p"
--
Safe
Eaton
Search vendor "Eaton"
Easy-e4-dc-8te1p Firmware
Search vendor "Eaton" for product "Easy-e4-dc-8te1p Firmware"
< 2.02
Search vendor "Eaton" for product "Easy-e4-dc-8te1p Firmware" and version " < 2.02"
-
Affected
in Eaton
Search vendor "Eaton"
Easy-e4-dc-8te1p
Search vendor "Eaton" for product "Easy-e4-dc-8te1p"
--
Safe
Eaton
Search vendor "Eaton"
Easy-e4-uc-12rc1p Firmware
Search vendor "Eaton" for product "Easy-e4-uc-12rc1p Firmware"
< 2.02
Search vendor "Eaton" for product "Easy-e4-uc-12rc1p Firmware" and version " < 2.02"
-
Affected
in Eaton
Search vendor "Eaton"
Easy-e4-uc-12rc1p
Search vendor "Eaton" for product "Easy-e4-uc-12rc1p"
--
Safe
Eaton
Search vendor "Eaton"
Easy-e4-uc-12rcx1p Firmware
Search vendor "Eaton" for product "Easy-e4-uc-12rcx1p Firmware"
< 2.02
Search vendor "Eaton" for product "Easy-e4-uc-12rcx1p Firmware" and version " < 2.02"
-
Affected
in Eaton
Search vendor "Eaton"
Easy-e4-uc-12rcx1p
Search vendor "Eaton" for product "Easy-e4-uc-12rcx1p"
--
Safe
Eaton
Search vendor "Eaton"
Easy-e4-uc-16re1 Firmware
Search vendor "Eaton" for product "Easy-e4-uc-16re1 Firmware"
< 2.02
Search vendor "Eaton" for product "Easy-e4-uc-16re1 Firmware" and version " < 2.02"
-
Affected
in Eaton
Search vendor "Eaton"
Easy-e4-uc-16re1
Search vendor "Eaton" for product "Easy-e4-uc-16re1"
--
Safe
Eaton
Search vendor "Eaton"
Easy-e4-uc-16re1p Firmware
Search vendor "Eaton" for product "Easy-e4-uc-16re1p Firmware"
< 2.02
Search vendor "Eaton" for product "Easy-e4-uc-16re1p Firmware" and version " < 2.02"
-
Affected
in Eaton
Search vendor "Eaton"
Easy-e4-uc-16re1p
Search vendor "Eaton" for product "Easy-e4-uc-16re1p"
--
Safe
Eaton
Search vendor "Eaton"
Easy-e4-uc-8re1p Firmware
Search vendor "Eaton" for product "Easy-e4-uc-8re1p Firmware"
< 2.02
Search vendor "Eaton" for product "Easy-e4-uc-8re1p Firmware" and version " < 2.02"
-
Affected
in Eaton
Search vendor "Eaton"
Easy-e4-uc-8re1p
Search vendor "Eaton" for product "Easy-e4-uc-8re1p"
--
Safe
Eaton
Search vendor "Eaton"
Xv-102-a035tqrb-1e4 Firmware
Search vendor "Eaton" for product "Xv-102-a035tqrb-1e4 Firmware"
< 2.02
Search vendor "Eaton" for product "Xv-102-a035tqrb-1e4 Firmware" and version " < 2.02"
-
Affected
in Eaton
Search vendor "Eaton"
Xv-102-a035tqrb-1e4
Search vendor "Eaton" for product "Xv-102-a035tqrb-1e4"
--
Safe
Eaton
Search vendor "Eaton"
Xv-102-a3-57tvrb-1e4 Firmware
Search vendor "Eaton" for product "Xv-102-a3-57tvrb-1e4 Firmware"
< 2.02
Search vendor "Eaton" for product "Xv-102-a3-57tvrb-1e4 Firmware" and version " < 2.02"
-
Affected
in Eaton
Search vendor "Eaton"
Xv-102-a3-57tvrb-1e4
Search vendor "Eaton" for product "Xv-102-a3-57tvrb-1e4"
--
Safe
Eaton
Search vendor "Eaton"
Xv100-box-e4-dc1 Firmware
Search vendor "Eaton" for product "Xv100-box-e4-dc1 Firmware"
< 2.02
Search vendor "Eaton" for product "Xv100-box-e4-dc1 Firmware" and version " < 2.02"
-
Affected
in Eaton
Search vendor "Eaton"
Xv100-box-e4-dc1
Search vendor "Eaton" for product "Xv100-box-e4-dc1"
--
Safe
Eaton
Search vendor "Eaton"
Xv100-box-e4-uc1 Firmware
Search vendor "Eaton" for product "Xv100-box-e4-uc1 Firmware"
< 2.02
Search vendor "Eaton" for product "Xv100-box-e4-uc1 Firmware" and version " < 2.02"
-
Affected
in Eaton
Search vendor "Eaton"
Xv100-box-e4-uc1
Search vendor "Eaton" for product "Xv100-box-e4-uc1"
--
Safe