CVE-2024-5434
The Campbell Scientific CSI Web Server stores web authentication credentials in a file with a specific file name. Passwords within that file are stored in a weakly encoded format. There is no known way to remotely access the file unless it has been manually renamed. However, if an attacker were to gain access to the file, passwords could be decoded and reused to gain access.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.9
- CVSS vector
- CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.22%
- CWE
- CWE-261
- Published
- 2024-05-28
- Last modified
- 2026-03-13
Affected products
- Campbell Scientific CSI Web Server and RTMC
- Campbell Scientific CSI Web Server and RTMC
Weakness type
Related vulnerabilities
- CVE-2026-63424 — During an internal security assessment, an improperly protected key was discovered in Lenovo Dock...
- CVE-2026-67596 — CSL 1010 M2M 3G WiFi Module 2.2.1.4 Weak Encryption via Router.cfg
- CVE-2026-53692 — Weak hashing algorithm in Redeight CMS
- CVE-2026-40639 — Dell Client Platform BIOS contains a Weak Encoding for Password vulnerability. An unauthenticated...
- CVE-2026-25607 — Weak password encoding in STER
- CVE-2025-11500 — Credentials exposure in tinycontrol devices
- CVE-2026-0809 — Weak KSeF token encoding in Streamsoft Prestiż
- CVE-2024-52334 — A vulnerability has been identified in syngo.plaza VB30E (All versions < VB30E_HF07). The affected...