CVE-2023-0452: Econolite Eos

Medium severity, CVSS 5.3. EPSS: 0.5% chance of exploitation in the next 30 days.

Econolite EOS versions prior to 3.2.23 use a weak hash algorithm for encrypting privileged user credentials. A configuration file that is accessible without authentication uses MD5 hashes for encrypting credentials, including those of administrators and technicians.

Affected products

Published 2023-01-26. Last modified 2026-06-17.