CVE Database
/

CVE-2018-19009

Back to search

CVE-2018-19009

Published: Jan 25, 2019

Modified: Sep 16, 2024

PUBLISHED

Description

Pilz PNOZmulti Configurator prior to version 10.9 allows an authenticated attacker with local access to the system containing the PNOZmulti Configurator software to view sensitive credential data in clear-text. This sensitive data is applicable to only the PMI m107 diag HMI device. An attacker with access to this sensitive data and physical access to the PMI m107 diag can modify data on the HMI device.

VendorProductVersions

Pilz

Pilz PNOZmulti Configurator

affected
All versions prior to version 10.9

Weaknesses (CWE)

References

106529
vdb-entry
x_refsource_BID

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now