### [CVE-2021-3252](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3252) ![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brighgreen) ### Description KACO New Energy XP100U Up to XP-JAVA 2.0 is affected by incorrect access control. Credentials will always be returned in plain-text from the local server during the KACO XP100U authentication process, regardless of whatever passwords have been provided, which leads to an information disclosure vulnerability. ### POC #### Reference - https://us-cert.cisa.gov/ics/alerts/ICS-ALERT-15-224-01 #### Github No PoCs found on GitHub currently.