CVE-2025-54818
Cognex In-Sight Explorer and In-Sight Camera Firmware Cleartext Transmission of Sensitive Information
Vexday Risk Score
21Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 8.6EPSS 0.1%KEV nãoPoC —Patch —
Ciclo de vida
18 sep 2025Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
Cognex In-Sight Explorer and In-Sight Camera Firmware expose
a proprietary protocol on TCP port 1069 to perform management operations
such as modifying system properties. The user management functionality
handles sensitive data such as registered usernames and passwords over
an unencrypted channel, allowing an adjacent attacker to intercept valid
credentials to gain access to the device.
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Productos afectados
Cognex · In-Sight 2000 seriesCognex · In-Sight 7000 seriesCognex · In-Sight 8000 seriesCognex · In-Sight 9000 seriesCognex · In-Sight Explorer¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →