CVE-2026-103548
Received Received - Intake

Improper Password Storage in Itron MV-90 xi

Vulnerability report for CVE-2026-103548, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: Palo Alto Networks, Inc.

Description

Improperly stored passwords in the config file in Itron MV-90 xi 3.0 allows attackers to decode the passwords and password histories to gain access to the MV-90 application as any user.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
itron mv-90 3.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-260 The product stores a password in a configuration file that might be accessible to actors who do not know the password.
CWE-257 The storage of passwords in a recoverable format makes them subject to password reuse attacks by malicious users. In fact, it should be noted that recoverable encrypted passwords provide no significant benefit over plaintext passwords since they are subject not only to reuse by malicious attackers but also by malicious insiders. If a system administrator can recover a password directly, or use a brute force search on the available information, the administrator can use the password on other accounts.
CWE-261 Obscuring a password with a trivial encoding does not protect the password.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Improperly stored passwords in the config file of Itron MV-90 xi 3.0 allow attackers to decode passwords and password histories, enabling unauthorized access to the MV-90 application as any user.

Detection Guidance

Check Itron MV-90 xi config files for improperly stored passwords. Look for encoded or plaintext password entries in configuration files or logs. Review files like mv90_config.xml or similar for suspicious password storage methods.

Impact Analysis

Attackers could gain full access to the MV-90 application, potentially compromising sensitive data, system operations, or user accounts. This could lead to data breaches, unauthorized modifications, or service disruptions.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR or HIPAA due to unauthorized access to sensitive data. GDPR requires protection of personal data, while HIPAA mandates safeguards for protected health information. A breach could result in legal penalties or fines.

Mitigation Strategies

Update Itron MV-90 xi to the latest version. Remove any stored passwords from config files and use secure password storage mechanisms. Restrict access to config files and monitor for unauthorized access attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103548. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart