SaTECH BCU Weak Password Encryption Vulnerability

Vulnerability

A vulnerability exists in the SaTECH BCU firmware version 2.1.3 due to inadequate password encryption. This weakness allows an attacker with access to the device's system or website to retrieve user credentials, as the encryption methods employed are insufficiently robust. The vulnerability affects SaTECH BCU, a control and automation device used for data acquisition and position control in electrical substations.

Impact

Exploitation of this vulnerability could lead to unauthorized access to user credentials, allowing attackers to log in as those users and potentially manipulate device settings or functions, depending on the user's privileges.

Remediation

Users can upgrade to SaTECH BCU firmware version 2.2.1 to address this vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
3.5
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.