---
id: CVE-2022-4312
title: >-

  A cleartext storage of sensitive information vulnerability exists in PcVue
  versions 8.10 through 15.2.3
summary: >-

  A cleartext storage of sensitive information vulnerability exists in PcVue
  versions 8.10 through 15.2.3. This could

  allow an unauthorized user with access the email and short messaging service
  (SMS) accounts configuration files

  to disco…
severity: medium
cvss: 5.5
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-312
  - CWE-522
vendor: arcinfo
product: pcvue
affected:
  - 'pcvue >= 8.10, <= 15.2.3'
published: '2022-12-12'
updated: '2026-07-09'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2022-4312'
references:
  - url: >-
      https://www.pcvuesolutions.com/support/index.php/en/security-bulletin/1171-security-bulletin-2022-7
    label: ics-cert@hq.dhs.gov
  - url: >-
      https://www.pcvuesolutions.com/support/index.php/en/security-bulletin/1171-security-bulletin-2022-7
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00118
epssPercentile: 0.01971
ingestedAt: '2026-07-10T01:55:22.867Z'
---

## Overview


A cleartext storage of sensitive information vulnerability exists in PcVue versions 8.10 through 15.2.3. This could
allow an unauthorized user with access the email and short messaging service (SMS) accounts configuration files
to discover the associated simple mail transfer protocol (SMTP) account credentials and the SIM card PIN code.
Successful exploitation of this vulnerability could allow an unauthorized user access to the underlying email
account and SIM card.



## Affected

- `pcvue >= 8.10, <= 15.2.3`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
