Severity

7.1

Vulnerability Type

Missing Encryption of Sensitive Data (CWE-311)

Summary

A local user may find a configuration file on the client workstation with unencrypted sensitive data. This allows an attacker to impersonate the device or prevent the device from accessing the cloud portal which leads to a DoS.