ID

VAR-201802-1343


TITLE

Multiple vulnerabilities in Sprecher AutomationSPRECON-E-C, PU-2433

Trust: 0.6

sources: CNVD: CNVD-2018-02693

DESCRIPTION

Sprecher Automation GmbH provides switching equipment and automation solutions for energy, industrial and infrastructure construction. Power facilities, industries, transportation companies, municipal utilities and public institutions are all customers. (1) The authentication path traversal vulnerability exists in the web interface of Sprecher PLC. Allow authenticated users to read target system files. (2) Sprecher Automation SPRECON-E-C, PU-2433 client has a password hashing vulnerability. Since the hash of the password is calculated on the browser side, the hash of the password can also be used for login. (3) Sprecher Automation SPRECON-E-C, PU-2433 There is an unauthorized access vulnerability in the Telnet management service. Because the PLC is open telnet management service on TCP/2048 port. This interface can be used to control the PLC without any authentication. (4) Sprecher Automation SPRECON-E-C, PU-2433 has a denial of service vulnerability. A positive TCP SYN scan of a large number of ports triggers a PLC denial of service. Causes DOS attacks. Manual intervention is required to restore service availability. (5) Sprecher Automation SPRECON-E-C, PU-2433 has an old kernel vulnerability. Because the Linux kernel version of the PLC operating system is too old. Lead to a large number of known security vulnerabilities, potential security risks

Trust: 0.72

sources: CNVD: CNVD-2018-02693 // IVD: e2e35191-39ab-11e9-9ac8-000c29342cb1

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.8

sources: IVD: e2e35191-39ab-11e9-9ac8-000c29342cb1 // CNVD: CNVD-2018-02693

AFFECTED PRODUCTS

vendor:sprecher automationmodel:sprecon-e-c pu-2433scope:ltversion:8.49

Trust: 0.6

vendor:sprecher automationmodel: - scope:eqversion:*

Trust: 0.2

vendor:sprechermodel:automation sprecon-e-c pu-2433scope:ltversion:8.49

Trust: 0.2

sources: IVD: e2e35191-39ab-11e9-9ac8-000c29342cb1 // CNVD: CNVD-2018-02693

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2018-02693
value: HIGH

Trust: 0.6

IVD: e2e35191-39ab-11e9-9ac8-000c29342cb1
value: HIGH

Trust: 0.2

CNVD: CNVD-2018-02693
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

IVD: e2e35191-39ab-11e9-9ac8-000c29342cb1
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.9 [IVD]

Trust: 0.2

sources: IVD: e2e35191-39ab-11e9-9ac8-000c29342cb1 // CNVD: CNVD-2018-02693

TYPE

other

Trust: 0.2

sources: IVD: e2e35191-39ab-11e9-9ac8-000c29342cb1

PATCH

title:Sprecher AutomationSPRECON-E-C, PU-2433 patch with multiple vulnerabilitiesurl:https://www.cnvd.org.cn/patchinfo/show/115605

Trust: 0.6

sources: CNVD: CNVD-2018-02693

EXTERNAL IDS

db:CNVDid:CNVD-2018-02693

Trust: 0.8

db:IVDid:E2E35191-39AB-11E9-9AC8-000C29342CB1

Trust: 0.2

sources: IVD: e2e35191-39ab-11e9-9ac8-000c29342cb1 // CNVD: CNVD-2018-02693

REFERENCES

url:http://seclists.org/fulldisclosure/2018/jan/101?utm_source=feedburner&utm_medium=twitter&utm_campaign=feed%3a+seclists%2ffulldisclosure+%28full+disclosure%29

Trust: 0.6

sources: CNVD: CNVD-2018-02693

SOURCES

db:IVDid:e2e35191-39ab-11e9-9ac8-000c29342cb1
db:CNVDid:CNVD-2018-02693

LAST UPDATE DATE

2022-05-17T01:45:10.750000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2018-02693date:2018-02-02T00:00:00

SOURCES RELEASE DATE

db:IVDid:e2e35191-39ab-11e9-9ac8-000c29342cb1date:2018-02-02T00:00:00
db:CNVDid:CNVD-2018-02693date:2018-02-02T00:00:00