← back
CVE-2012-1977CWE-311

WellinTech KingSCADA Missing Encryption of Sensitive Data

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 7.1epss 0.8%
exploitation probability
0.8%top 47% of all CVEs
observed exploitation
nono source reports it
WellinTech KingSCADA 3.0 uses a cleartext base64 format for storage of passwords in user.db, which allows context-dependent attackers to obtain sensitive information by reading this file.
AV:N/AC:M/Au:N/C:C/I:N/A:N
Affected products
WellinTech · KingSCADA