Echelon SmartServer 1 all versions, SmartServer 2 all versions prior to release 4.11.007, i.LON 100 all versions, and i.LON 600 all versions. The devices store passwords in plaintext, which may allow an attacker with access to the configuration file to log into the SmartServer web user interface.
Project Subscriptions
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-20459 | Echelon SmartServer 1 all versions, SmartServer 2 all versions prior to release 4.11.007, i.LON 100 all versions, and i.LON 600 all versions. The devices store passwords in plaintext, which may allow an attacker with access to the configuration file to log into the SmartServer web user interface. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://ics-cert.us-cert.gov/advisories/ICSA-18-200-03 |
|
History
Wed, 03 Jun 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2026-06-02T19:58:52.622Z
Reserved: 2018-03-20T00:00:00.000Z
Link: CVE-2018-8851
Updated: 2024-08-05T07:10:45.892Z
Status : Modified
Published: 2018-07-24T17:29:00.353
Modified: 2026-06-02T21:16:22.350
Link: CVE-2018-8851
No data.
OpenCVE Enrichment
No data.
EUVD