ID

VAR-201909-1553


TITLE

NAPro has a backdoor vulnerability

Trust: 0.6

sources: CNVD: CNVD-2019-32858

DESCRIPTION

NAPro is a PLC programming software developed by Nanda Autotech Jiangsu Co., Ltd. NAPro has a backdoor vulnerability. Attackers can use this vulnerability to log in to the PLC to perform illegal operations

Trust: 0.72

sources: CNVD: CNVD-2019-32858 // IVD: c9149fdf-7844-42d1-8dec-86d12512f10d

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.8

sources: IVD: c9149fdf-7844-42d1-8dec-86d12512f10d // CNVD: CNVD-2019-32858

AFFECTED PRODUCTS

vendor:nanda autotech jiangsumodel:naproscope: - version: -

Trust: 0.6

vendor:nanda auto jiangsumodel:naproscope:eqversion:*

Trust: 0.2

sources: IVD: c9149fdf-7844-42d1-8dec-86d12512f10d // CNVD: CNVD-2019-32858

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2019-32858
value: MEDIUM

Trust: 0.6

IVD: c9149fdf-7844-42d1-8dec-86d12512f10d
value: MEDIUM

Trust: 0.2

CNVD: CNVD-2019-32858
severity: MEDIUM
baseScore: 6.6
vectorString: AV:L/AC:L/AU:N/C:C/I:N/A:C
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 3.9
impactScore: 9.2
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

IVD: c9149fdf-7844-42d1-8dec-86d12512f10d
severity: MEDIUM
baseScore: 6.6
vectorString: AV:L/AC:L/AU:N/C:C/I:N/A:C
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 3.9
impactScore: 9.2
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.9 [IVD]

Trust: 0.2

sources: IVD: c9149fdf-7844-42d1-8dec-86d12512f10d // CNVD: CNVD-2019-32858

TYPE

back door

Trust: 0.2

sources: IVD: c9149fdf-7844-42d1-8dec-86d12512f10d

PATCH

title:Nanda Auto NAPro has a backdoor vulnerabilityurl:https://www.cnvd.org.cn/patchinfo/show/179109

Trust: 0.6

sources: CNVD: CNVD-2019-32858

EXTERNAL IDS

db:CNVDid:CNVD-2019-32858

Trust: 0.8

db:IVDid:C9149FDF-7844-42D1-8DEC-86D12512F10D

Trust: 0.2

sources: IVD: c9149fdf-7844-42d1-8dec-86d12512f10d // CNVD: CNVD-2019-32858

SOURCES

db:IVDid:c9149fdf-7844-42d1-8dec-86d12512f10d
db:CNVDid:CNVD-2019-32858

LAST UPDATE DATE

2022-05-17T02:02:22.807000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2019-32858date:2020-03-10T00:00:00

SOURCES RELEASE DATE

db:IVDid:c9149fdf-7844-42d1-8dec-86d12512f10ddate:2019-09-24T00:00:00
db:CNVDid:CNVD-2019-32858date:2019-10-19T00:00:00