---
id: CVE-2022-2569
title: >-
  The affected device stores sensitive information in cleartext, which may allow
  an authenticated user to access session data stored in the OAuth database
  belonging to legitimate users
summary: >-
  The affected device stores sensitive information in cleartext, which may allow
  an authenticated user to access session data stored in the OAuth database
  belonging to legitimate users
severity: medium
cvss: 5.5
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-312
vendor: arcinfo
product: pcvue
affected:
  - pcvue < 12.0.27
  - 'pcvue >= 15, <= 15.2.2'
patched:
  - pcvue 12.0.27
published: '2022-08-24'
updated: '2026-07-09'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2022-2569'
references:
  - url: 'https://www.cisa.gov/uscert/ics/advisories/icsa-22-235-01-0'
    label: ics-cert@hq.dhs.gov
  - url: 'https://www.cisa.gov/uscert/ics/advisories/icsa-22-235-01-0'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00137
epssPercentile: 0.03498
ingestedAt: '2026-07-10T01:55:22.850Z'
---

## Overview

The affected device stores sensitive information in cleartext, which may allow an authenticated user to access session data stored in the OAuth database belonging to legitimate users

## Affected

- `pcvue < 12.0.27`
- `pcvue >= 15, <= 15.2.2`

## Remediation

Upgrade past the affected range:

- `pcvue 12.0.27`
