CVE-2019-11369 EXPLOIT
8.8
HIGH · CVSS 3.0 · EPSS 8.1% (pctl 95)
Patch early
A public exploit exists.
Description
An issue was discovered in Carel pCOWeb prior to B1.2.4. In /config/pw_changeusers.html the device stores cleartext passwords, which may allow sensitive information to be read by someone with access to the device.
Scoring
| CVSS | 8.8 (HIGH, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 8.14% — more likely to be exploited than 95% of all CVEs |
| Weakness | CWE-522 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2019-06-03 |
| Last modified | 2026-06-17 |
Affected (2)
| Vendor | Product |
|---|---|
| carel | pcoweb card |
| carel | pcoweb card firmware |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Carel pCOWeb < B1.2.1 - Credentials Disclosure | 2019-05-22 |
References
- http://seclists.org/fulldisclosure/2019/Oct/45
- https://drive.google.com/open?id=12Sq6oaxe1mC1y71Emo1YladjDjwTdNfb
- https://github.com/nepenthe0320/cve_poc/blob/master/CVE-2019-11369
- http://seclists.org/fulldisclosure/2019/Oct/45
- https://drive.google.com/open?id=12Sq6oaxe1mC1y71Emo1YladjDjwTdNfb
- https://github.com/nepenthe0320/cve_poc/blob/master/CVE-2019-11369
→ the Explorer · watch your stack · NVD