MEDIUM · 6.8

CVE-2023-43776

Eaton easyE4 PLC offers a device password protection functionality to facilitate a secure connection and prevent unauthorized access. It was observed that the device password was stored with a weak en...

Vulnerability Description

Eaton easyE4 PLC offers a device password protection functionality to facilitate a secure connection and prevent unauthorized access. It was observed that the device password was stored with a weak encoding algorithm in the easyE4 program file when exported to SD card (*.PRG file ending).

CVSS Score

6.8

MEDIUM

CVSS:3.1/AV:P/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H
Attack Vector
PHYSICAL
Attack Complexity
HIGH
Privileges Required
HIGH
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
EatonEasy-Box-E4-Ac1 Firmware< 2.02
EatonEasy-Box-E4-Ac1-
EatonEasy-Box-E4-Dc1 Firmware< 2.02
EatonEasy-Box-E4-Dc1-
EatonEasy-Box-E4-Uc1 Firmware< 2.02
EatonEasy-Box-E4-Uc1-
EatonEasy-E4-Ac-12Rc1P Firmware< 2.02
EatonEasy-E4-Ac-12Rc1P-
EatonEasy-E4-Ac-12Rcx1P Firmware< 2.02
EatonEasy-E4-Ac-12Rcx1P-
EatonEasy-E4-Ac-16Re1P Firmware< 2.02
EatonEasy-E4-Ac-16Re1P-
EatonEasy E4-Ac-8Re1P Firmware< 2.02
EatonEasy E4-Ac-8Re1P-
EatonEasy-E4-Dc-12Tc1P Firmware< 2.02
EatonEasy-E4-Dc-12Tc1P-
EatonEasy-E4-Dc-12Tcx1P Firmware< 2.02
EatonEasy-E4-Dc-12Tcx1P-
EatonEasy-E4-Dc-16Te1P Firmware< 2.02
EatonEasy-E4-Dc-16Te1P-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2023-43776?

CVE-2023-43776 is a vulnerability with a CVSS score of 6.8 (MEDIUM). Eaton easyE4 PLC offers a device password protection functionality to facilitate a secure connection and prevent unauthorized access. It was observed that the device password was stored with a weak en...

How severe is CVE-2023-43776?

CVE-2023-43776 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2023-43776?

Check the references section above for vendor advisories and patch information. Affected products include: Eaton Easy-Box-E4-Ac1 Firmware, Eaton Easy-Box-E4-Ac1, Eaton Easy-Box-E4-Dc1 Firmware, Eaton Easy-Box-E4-Dc1, Eaton Easy-Box-E4-Uc1 Firmware.