SaTECH BCU Weak Password Encryption Vulnerability
Vulnerability
A vulnerability exists in the SaTECH BCU firmware version 2.1.3 due to inadequate password encryption. This weakness allows an attacker with access to the device's system or website to retrieve user credentials, as the encryption methods employed are insufficiently robust. The vulnerability affects SaTECH BCU, a control and automation device used for data acquisition and position control in electrical substations.
Impact
Exploitation of this vulnerability could lead to unauthorized access to user credentials, allowing attackers to log in as those users and potentially manipulate device settings or functions, depending on the user's privileges.
Remediation
Users can upgrade to SaTECH BCU firmware version 2.2.1 to address this vulnerability.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
