### [CVE-2024-41716](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-41716) ![](https://img.shields.io/static/v1?label=Product&message=WindLDR&color=blue) ![](https://img.shields.io/static/v1?label=Product&message=WindO%2FI-NV4&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=Ver.3.0.1%20&color=brightgreen) ![](https://img.shields.io/static/v1?label=Version&message=Ver.9.1.0%20and%20earlier%20&color=brightgreen) ![](https://img.shields.io/static/v1?label=Vulnerability&message=Cleartext%20storage%20of%20sensitive%20information&color=brightgreen) ### Description Cleartext storage of sensitive information vulnerability exists in WindLDR and WindO/I-NV4. If this vulnerability is exploited, an attacker who obtained the product's project file may obtain user credentials of the PLC or Operator Interfaces. As a result, an attacker may be able to manipulate and/or suspend the PLC and Operator Interfaces by accessing or hijacking them. ### POC #### Reference No PoCs from references. #### Github - https://github.com/fkie-cad/nvd-json-data-feeds