CVE-2026-103548
Received
Received - Intake
Improper Password Storage in Itron MV-90 xi
Vulnerability report for CVE-2026-103548, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-09-30
Last updated on: 2026-09-30
Assigner: Palo Alto Networks, Inc.
Description
Description
Improperly stored passwords in the config file in Itron MV-90 xi 3.0 allows attackers to decode the passwords and password histories to gain access to the MV-90 application as any user.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| itron | mv-90 | 3.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-260 | The product stores a password in a configuration file that might be accessible to actors who do not know the password. |
| CWE-257 | The storage of passwords in a recoverable format makes them subject to password reuse attacks by malicious users. In fact, it should be noted that recoverable encrypted passwords provide no significant benefit over plaintext passwords since they are subject not only to reuse by malicious attackers but also by malicious insiders. If a system administrator can recover a password directly, or use a brute force search on the available information, the administrator can use the password on other accounts. |
| CWE-261 | Obscuring a password with a trivial encoding does not protect the password. |