{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-06-15T07:51:08.316","vulnerabilities":[{"cve":{"id":"CVE-2022-3089","sourceIdentifier":"ics-cert@hq.dhs.gov","published":"2023-02-13T17:15:10.763","lastModified":"2024-11-21T07:18:48.187","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"\n\n\n\n\nEchelon SmartServer 2.2 with i.LON Vision 2.2 stores cleartext credentials in a file, which could allow an attacker to obtain cleartext usernames and passwords of the SmartServer. If the attacker obtains the file, then the credentials could be used to control the web user interface and file transfer protocol (FTP) server. \n\n \n\n"},{"lang":"es","value":"Echelon SmartServer 2.2 con i.LON Vision 2.2 almacena las credenciales en texto plano en un archivo, lo que podría permitir a un atacante obtener nombres de usuario y contraseñas en texto plano del SmartServer. Si el atacante obtiene el archivo, las credenciales podrían usarse para controlar la interfaz de usuario web y el servidor del protocolo de transferencia de archivos (FTP)."}],"metrics":{"cvssMetricV31":[{"source":"ics-cert@hq.dhs.gov","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:H","baseScore":6.3,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"HIGH"},"exploitabilityScore":0.8,"impactScore":5.5},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}]},"weaknesses":[{"source":"ics-cert@hq.dhs.gov","type":"Secondary","description":[{"lang":"en","value":"CWE-798"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-312"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:echelon:i.lon_vision:2.2:*:*:*:*:*:*:*","matchCriteriaId":"50970A8A-CC8A-49DA-96EB-18C2E92E4420"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:echelon:smartserver:2.2:*:*:*:*:*:*:*","matchCriteriaId":"1685E1B3-A7F7-4E0F-9BFB-C0CC09739D2B"}]}]}],"references":[{"url":"https://www.cisa.gov/uscert/ics/advisories/icsa-23-037-01","source":"ics-cert@hq.dhs.gov","tags":["Broken Link"]},{"url":"https://www.cisa.gov/uscert/ics/advisories/icsa-23-037-01","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]}]}}]}