In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.9 a form...
Moderate severity
Unreviewed
Published
May 24, 2022
to the GitHub Advisory Database
•
Updated Jan 28, 2023
Description
Published by the National Vulnerability Database
Aug 31, 2021
Published to the GitHub Advisory Database
May 24, 2022
Last updated
Jan 28, 2023
In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.9 a form contains a password field with autocomplete enabled. The stored credentials can be captured by an attacker who gains control over the user's computer. Therefore the user must have logged in at least once.
References