CVE-2021-3252
Description
KACO New Energy XP100U Up to XP-JAVA 2.0 is affected by incorrect access control. Credentials will always be returned in plain-text from the local server during the KACO XP100U authentication process, regardless of whatever passwords have been provided, which leads to an information disclosure vulnerability.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- KACO New Energy/XP100Udescription
- Range: <= XP-JAVA 2.0
Patches
Vulnerability mechanics
Root cause
"Hard-coded credentials present in the client-side code allow anyone who inspects the client to obtain plain-text passwords."
Attack vector
An attacker can remotely exploit the hard-coded password by extracting credentials from the client-side code, which is easily accessible [ref_id=1]. The advisory notes the vulnerability is remotely exploitable and could lead to remote code execution [ref_id=1]. The attacker does not need valid authentication because the credentials are embedded in the client software itself.
Affected code
The advisory [ref_id=1] states that "the passwords for KACO HMI products are present in the code for the client that allows users to control the HMI." No specific file paths or function names are provided in the bundle.
What the fix does
The bundle does not include a patch. The advisory [ref_id=1] states that ICS-CERT is coordinating with the vendor to identify mitigations and will notify users when a patch or other mitigating solution becomes available. No remediation code or vendor fix is published in the provided materials.
Preconditions
- networkAttacker must have network access to the KACO HMI device
- authNo authentication required; credentials are hard-coded in the client code
Generated on May 25, 2026. Inputs: CWE entries + fix-commit diffs from this CVE's patches. Citations validated against bundle.
References
3- tiger-team-1337.blogspot.com/2021/01/kaco-xp100u-hmi-credential-leak.htmlmitrex_refsource_MISC
- twitter.com/Kevin2600/status/1351189347501023238mitrex_refsource_MISC
- us-cert.cisa.gov/ics/alerts/ICS-ALERT-15-224-01mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.