CVE-2026-35556 PUBLISHED

Plaintext storage of a password in OpenPLC_V3

Assigner: icscert
Reserved: 06.04.2026 Published: 09.04.2026 Updated: 09.04.2026

OpenPLC_V3 is vulnerable to a Plaintext Storage of a Password vulnerability that could allow an attacker to retrieve credentials and access sensitive information.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 9.2

Product Status

Vendor OpenPLC_V3
Product OpenPLC_V3
Versions Default: unaffected
  • Version All versions is affected

Workarounds

OpenPLC_v3 is now considered to be end of life. Users are recommended to upgrade to OpenPLC Runtime v4 ( https://github.com/autonomy-logic/openplc-runtime ).

Credits

  • Shriyans Sudhi (ss0x00) from Rochester Institute of Technology (RIT) finder

References

Problem Types

  • CWE-256 Plaintext storage of a password CWE