ID

VAR-201909-1564


TITLE

Authentication Bypass Vulnerability in Unity Pro XL

Trust: 0.6

sources: CNVD: CNVD-2019-32855

DESCRIPTION

Unity Pro XL is a PLC programming software from Schneider Electric. There is an authentication bypass vulnerability in Unity Pro XL, which can be used by unauthorized attackers to access the PLC

Trust: 0.72

sources: CNVD: CNVD-2019-32855 // IVD: e40838af-2d6b-4867-a498-32ec14d73e1e

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.8

sources: IVD: e40838af-2d6b-4867-a498-32ec14d73e1e // CNVD: CNVD-2019-32855

AFFECTED PRODUCTS

vendor:schneidermodel:electric unity pro xlscope:eqversion:v13.0

Trust: 0.8

sources: IVD: e40838af-2d6b-4867-a498-32ec14d73e1e // CNVD: CNVD-2019-32855

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2019-32855
value: MEDIUM

Trust: 0.6

IVD: e40838af-2d6b-4867-a498-32ec14d73e1e
value: MEDIUM

Trust: 0.2

CNVD: CNVD-2019-32855
severity: MEDIUM
baseScore: 6.6
vectorString: AV:L/AC:L/AU:N/C:C/I:N/A:C
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 3.9
impactScore: 9.2
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

IVD: e40838af-2d6b-4867-a498-32ec14d73e1e
severity: MEDIUM
baseScore: 6.6
vectorString: AV:L/AC:L/AU:N/C:C/I:N/A:C
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 3.9
impactScore: 9.2
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.9 [IVD]

Trust: 0.2

sources: IVD: e40838af-2d6b-4867-a498-32ec14d73e1e // CNVD: CNVD-2019-32855

TYPE

Access verification error

Trust: 0.2

sources: IVD: e40838af-2d6b-4867-a498-32ec14d73e1e

PATCH

title:Schneider M580 Series Device Has Authentication Logic Defect Vulnerabilityurl:https://www.cnvd.org.cn/patchinfo/show/179299

Trust: 0.6

sources: CNVD: CNVD-2019-32855

EXTERNAL IDS

db:CNVDid:CNVD-2019-32855

Trust: 0.8

db:IVDid:E40838AF-2D6B-4867-A498-32EC14D73E1E

Trust: 0.2

sources: IVD: e40838af-2d6b-4867-a498-32ec14d73e1e // CNVD: CNVD-2019-32855

SOURCES

db:IVDid:e40838af-2d6b-4867-a498-32ec14d73e1e
db:CNVDid:CNVD-2019-32855

LAST UPDATE DATE

2022-05-17T02:08:54.871000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2019-32855date:2019-09-25T00:00:00

SOURCES RELEASE DATE

db:IVDid:e40838af-2d6b-4867-a498-32ec14d73e1edate:2019-09-24T00:00:00
db:CNVDid:CNVD-2019-32855date:2019-10-19T00:00:00