Texas Instruments Fusion Digital Power Designer 7.10.1 Credential Disclosure ≈ Packet Storm

Home[1] Files[2] News[3] &[SERVICES_TAB] Contact[4] Add New[5]

Texas Instruments Fusion Digital Power Designer 7.10.1 Credential Disclosure[6]
Authored by Gionathan Armando Reale[7]

Texas Instruments Fusion Digital Power Designer version 7.10.1 allows a local attacker to obtain sensitive information via the plaintext storage of credentials.

advisories | CVE-2024-41629[8]
SHA-256 | 7d2282798e3247a2123a5993d7d6d2cb77a3755e9e0270c916b57856fbfaf0ef

Change Mirror[12] Download[13]

Insufficiently Protected Credentials in Texas Instruments Fusion Digital Power Designer v.7.10.1
Credit: Gionathan Armando Reale
//////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////
# Product: Fusion Digital Power Designer - Version 7.10.1
# Vendor: Texas Instruments
# CVE ID: CVE-2024-41629
# Vulnerability Title: Insufficiently Protected Credentials
# Severity: Medium
# Author(s): Gionathan Armando Reale
# Date: 2024-08-15
#
#############################################################
Introduction:
An issue in Texas Instruments Fusion Digital Power Designer v.7.10.1 allows a local attacker to obtain sensitive information via the plaintext storage of credentials.
Vulnerability PoC:
1. Create a connection within the application that requires credentials.
2. Access the file "C:/Program Files (x86)/Texas Instruments/Fusion Digial Power Designer/data/prefs-shared.xml"
3. Notice the credentials stored as plaintext.
/////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////

Login[14] or Register[15] to add favorites

File Archive:

September 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa

File Tags

File Archives

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services[120]
Hosting By
Rokasec[121]
close
Image

Pensée du jour :

Ce que l'homme a fait ,

l'homme peut le défaire.

 

"No secure path in the world"