PT-2015-3360 · En100 · En100 Ethernet Module Modbus Tcp+4

Aleksey Stennikov

+2

·

Publicado

2015-12-17

·

Atualizado

2019-10-03

·

CVE-2018-4838

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions EN100 Ethernet module IEC 61850 variant versions prior to V4.30 EN100 Ethernet module DNP3 variant versions prior to V1.04 EN100 Ethernet module PROFINET IO variant (all versions) EN100 Ethernet module Modbus TCP variant (all versions) EN100 Ethernet module IEC 104 variant versions prior to V1.22
Description A vulnerability has been identified that allows an unauthenticated user to upgrade or downgrade the firmware of the device using the web interface (TCP/80), potentially installing older versions with known vulnerabilities. The issue is related to inadequate access control, which can be exploited remotely without authentication, enabling the installation of firmware, including versions containing known vulnerabilities.
Recommendations For EN100 Ethernet module IEC 61850 variant versions prior to V4.30, update to version V4.30 or later. For EN100 Ethernet module DNP3 variant versions prior to V1.04, update to version V1.04 or later. For EN100 Ethernet module PROFINET IO variant, restrict access to the web interface (TCP/80) until a fix is available. For EN100 Ethernet module Modbus TCP variant, restrict access to the web interface (TCP/80) until a fix is available. For EN100 Ethernet module IEC 104 variant versions prior to V1.22, update to version V1.22 or later.

Correção

Missing Authentication

Improper Access Control

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2018-00495
CVE-2018-4838

Produtos afetados

En100 Ethernet Module Dnp3
En100 Ethernet Module Iec 104
En100 Ethernet Module Iec 61850
En100 Ethernet Module Modbus Tcp
En100 Ethernet Module Profinet Io