ID

VAR-201711-0006


CVE

CVE-2016-0872


TITLE

Kabona AB WebDatorCentral Vulnerabilities related to certificate and password management

Trust: 0.8

sources: JVNDB: JVNDB-2016-008862

DESCRIPTION

A Plaintext Storage of a Password issue was discovered in Kabona AB WebDatorCentral (WDC) versions prior to Version 3.4.0. WDC stores password credentials in plaintext. Kabona AB WebDatorCentral (WDC) Contains vulnerabilities related to certificate and password management.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. Kabona AB WebDatorCentral (WDC) is a web-based SCADA system from Kabona AB, Sweden. An attacker could exploit the vulnerability to obtain information

Trust: 2.34

sources: NVD: CVE-2016-0872 // JVNDB: JVNDB-2016-008862 // CNVD: CNVD-2017-35245 // IVD: e2debdae-39ab-11e9-b1ba-000c29342cb1

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.8

sources: IVD: e2debdae-39ab-11e9-b1ba-000c29342cb1 // CNVD: CNVD-2017-35245

AFFECTED PRODUCTS

vendor:kabonamodel:webdatorcentralscope:ltversion:3.4.0

Trust: 1.0

vendor:kabona abmodel:webdatorcentralscope:ltversion:3.4.0

Trust: 0.8

vendor:kabonamodel:ab webdatorcentralscope:ltversion:3.4.0

Trust: 0.6

vendor:webdatorcentralmodel: - scope:eqversion:*

Trust: 0.2

sources: IVD: e2debdae-39ab-11e9-b1ba-000c29342cb1 // CNVD: CNVD-2017-35245 // JVNDB: JVNDB-2016-008862 // NVD: CVE-2016-0872

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2016-0872
value: CRITICAL

Trust: 1.0

NVD: CVE-2016-0872
value: CRITICAL

Trust: 0.8

CNVD: CNVD-2017-35245
value: HIGH

Trust: 0.6

CNNVD: CNNVD-201711-242
value: MEDIUM

Trust: 0.6

IVD: e2debdae-39ab-11e9-b1ba-000c29342cb1
value: MEDIUM

Trust: 0.2

nvd@nist.gov: CVE-2016-0872
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2017-35245
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

IVD: e2debdae-39ab-11e9-b1ba-000c29342cb1
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.9 [IVD]

Trust: 0.2

nvd@nist.gov: CVE-2016-0872
baseSeverity: CRITICAL
baseScore: 9.8
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 5.9
version: 3.0

Trust: 1.8

sources: IVD: e2debdae-39ab-11e9-b1ba-000c29342cb1 // CNVD: CNVD-2017-35245 // JVNDB: JVNDB-2016-008862 // CNNVD: CNNVD-201711-242 // NVD: CVE-2016-0872

PROBLEMTYPE DATA

problemtype:CWE-255

Trust: 1.8

sources: JVNDB: JVNDB-2016-008862 // NVD: CVE-2016-0872

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201711-242

TYPE

Trust management

Trust: 0.8

sources: IVD: e2debdae-39ab-11e9-b1ba-000c29342cb1 // CNNVD: CNNVD-201711-242

CONFIGURATIONS

sources: JVNDB: JVNDB-2016-008862

PATCH

title:WebDatorCentral (WDC)url:http://www.kabona.com/building-automation/wdc/

Trust: 0.8

title:Kabona AB WebDatorCentral password plaintext storage vulnerability patchurl:https://www.cnvd.org.cn/patchInfo/show/107043

Trust: 0.6

title:Kabona AB WebDatorCentral Security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=76184

Trust: 0.6

sources: CNVD: CNVD-2017-35245 // JVNDB: JVNDB-2016-008862 // CNNVD: CNNVD-201711-242

EXTERNAL IDS

db:NVDid:CVE-2016-0872

Trust: 3.2

db:ICS CERTid:ICSA-16-287-07

Trust: 3.0

db:CNVDid:CNVD-2017-35245

Trust: 0.8

db:CNNVDid:CNNVD-201711-242

Trust: 0.8

db:JVNDBid:JVNDB-2016-008862

Trust: 0.8

db:IVDid:E2DEBDAE-39AB-11E9-B1BA-000C29342CB1

Trust: 0.2

sources: IVD: e2debdae-39ab-11e9-b1ba-000c29342cb1 // CNVD: CNVD-2017-35245 // JVNDB: JVNDB-2016-008862 // CNNVD: CNNVD-201711-242 // NVD: CVE-2016-0872

REFERENCES

url:https://ics-cert.us-cert.gov/advisories/icsa-16-287-07

Trust: 3.0

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2016-0872

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2016-0872

Trust: 0.8

sources: CNVD: CNVD-2017-35245 // JVNDB: JVNDB-2016-008862 // CNNVD: CNNVD-201711-242 // NVD: CVE-2016-0872

SOURCES

db:IVDid:e2debdae-39ab-11e9-b1ba-000c29342cb1
db:CNVDid:CNVD-2017-35245
db:JVNDBid:JVNDB-2016-008862
db:CNNVDid:CNNVD-201711-242
db:NVDid:CVE-2016-0872

LAST UPDATE DATE

2025-04-20T23:13:19.291000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2017-35245date:2017-11-28T00:00:00
db:JVNDBid:JVNDB-2016-008862date:2017-12-05T00:00:00
db:CNNVDid:CNNVD-201711-242date:2017-11-09T00:00:00
db:NVDid:CVE-2016-0872date:2025-04-20T01:37:25.860

SOURCES RELEASE DATE

db:IVDid:e2debdae-39ab-11e9-b1ba-000c29342cb1date:2017-11-28T00:00:00
db:CNVDid:CNVD-2017-35245date:2017-11-28T00:00:00
db:JVNDBid:JVNDB-2016-008862date:2017-12-05T00:00:00
db:CNNVDid:CNNVD-201711-242date:2017-11-09T00:00:00
db:NVDid:CVE-2016-0872date:2017-11-07T21:29:00.260