ID

VAR-201207-0679


TITLE

Kessler Ellis Products Infilink HMI Unauthorized Access Vulnerability

Trust: 1.7

sources: IVD: cccf47e4-1f5d-11e6-abef-000c29c66e3d // CNVD: CNVD-2012-4025 // BID: 54728 // CNNVD: CNNVD-201210-560

DESCRIPTION

Kessler-Ellis is a well-known instrument manufacturer. The Infilink HMI is the Human Machine Interface (HMI) for Kessler-Ellis products. The Kessler Ellis Products Infilink HMI product failed to securely hash the authentication credentials in the project file. This product uses a simple binary XOR process to encrypt the plaintext password, allowing the attacker to simply extract the password information and control the application. Kessler-Ellis Products Infilink-HMI is prone to an unauthorized-access vulnerability. Local attackers can exploit this issue to gain unauthorized access to the affected application. This may aid in further attacks. Infilink-HMI 5.00.23 is vulnerable. Infilink HMI Yes Kessler-Ellis HMI of the product (HMI)

Trust: 0.99

sources: CNVD: CNVD-2012-4025 // BID: 54728 // IVD: cccf47e4-1f5d-11e6-abef-000c29c66e3d

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.8

sources: IVD: cccf47e4-1f5d-11e6-abef-000c29c66e3d // CNVD: CNVD-2012-4025

AFFECTED PRODUCTS

vendor:kesslermodel:ellis products infilink hmiscope:eqversion:5.00.23

Trust: 0.8

vendor:kessler ellismodel:products infilink-hmiscope:eqversion:5.0.23

Trust: 0.3

sources: IVD: cccf47e4-1f5d-11e6-abef-000c29c66e3d // CNVD: CNVD-2012-4025 // BID: 54728

CVSS

SEVERITY

CVSSV2

CVSSV3

IVD: cccf47e4-1f5d-11e6-abef-000c29c66e3d
value: MEDIUM

Trust: 0.2

IVD: cccf47e4-1f5d-11e6-abef-000c29c66e3d
severity: NONE
baseScore: NONE
vectorString: NONE
accessVector: NONE
accessComplexity: NONE
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: UNKNOWN

Trust: 0.2

sources: IVD: cccf47e4-1f5d-11e6-abef-000c29c66e3d

THREAT TYPE

local

Trust: 0.9

sources: BID: 54728 // CNNVD: CNNVD-201210-560

TYPE

Design Error

Trust: 0.3

sources: BID: 54728

EXTERNAL IDS

db:BIDid:54728

Trust: 1.5

db:ICS CERT ALERTid:ICS-ALERT-12-212-01

Trust: 0.9

db:CNVDid:CNVD-2012-4025

Trust: 0.8

db:CNNVDid:CNNVD-201210-560

Trust: 0.6

db:IVDid:CCCF47E4-1F5D-11E6-ABEF-000C29C66E3D

Trust: 0.2

sources: IVD: cccf47e4-1f5d-11e6-abef-000c29c66e3d // CNVD: CNVD-2012-4025 // BID: 54728 // CNNVD: CNNVD-201210-560

REFERENCES

url:http://www.us-cert.gov/control_systems/pdf/ics-alert-12-212-01.pdf

Trust: 0.9

url:http://www.securityfocus.com/bid/54728

Trust: 0.6

url:http://www.kep.com/infilink/infilink.html

Trust: 0.3

sources: CNVD: CNVD-2012-4025 // BID: 54728 // CNNVD: CNNVD-201210-560

CREDITS

Dr. Wesley McGrew of Mississippi State University.

Trust: 0.9

sources: BID: 54728 // CNNVD: CNNVD-201210-560

SOURCES

db:IVDid:cccf47e4-1f5d-11e6-abef-000c29c66e3d
db:CNVDid:CNVD-2012-4025
db:BIDid:54728
db:CNNVDid:CNNVD-201210-560

LAST UPDATE DATE

2022-05-17T01:46:38.949000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2012-4025date:2012-08-01T00:00:00
db:BIDid:54728date:2012-07-29T00:00:00
db:CNNVDid:CNNVD-201210-560date:2012-10-24T00:00:00

SOURCES RELEASE DATE

db:IVDid:cccf47e4-1f5d-11e6-abef-000c29c66e3ddate:2012-08-01T00:00:00
db:CNVDid:CNVD-2012-4025date:2012-08-01T00:00:00
db:BIDid:54728date:2012-07-29T00:00:00
db:CNNVDid:CNNVD-201210-560date:2012-07-29T00:00:00