Cognex In-Sight Products Cleartext Transmission of User-Credentials Vulnerability

Vulnerability

A vulnerability exists in multiple Cognex In-Sight products, including the In-Sight 2000, 7000, 8000, and 9000 series, as well as In-Sight Explorer, all running versions 5.x prior to 6.5.1. This vulnerability allows an adjacent attacker without authentication to intercept user-privileged credentials during the firmware upgrade process, exploiting cleartext transmission of sensitive information.

Impact

Successful exploitation allows adjacent attackers to retrieve user-privileged credentials, which could be used to gain unauthorized access to the device or its functions.

Remediation

Cognex advises users to switch to next-generation In-Sight Vision Suite-based systems, such as the In-Sight 2800, 3800, or 8900 series embedded cameras. For additional guidance, refer to the CISA ICS webpage and the technical information paper ICS-TIP-12-146-01B.

Added: Sep 18, 2025, 9:21 PM
Updated: Sep 18, 2025, 11:19 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
4.9
remediation
0.0
relevance
0.5
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.