CVE-2017-20040 describes a weak encryption vulnerability in the password storage component of SICUNET Access Controller 0.32-05z. This flaw allows an attacker with local access to potentially recover sensitive password information due to inadequate cryptographic practices. Rated as MEDIUM severity (CVSS 5.5), successful exploitation requires local access and could lead to high confidentiality impact, but does not affect integrity or availability. There is currently no public exploit code available (Metasploit, Nuclei, ExploitDB), and the vulnerability has received no community discussion or media coverage, indicating a low level of public awareness and no evidence of active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.32-05zCPE matchmatch criteria | cpe:2.3:a:sicunet:access_control:0.32-05z:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.