PT-2017-2831 · Marel Food Processing Systems · Mac4 Controller+6

Publicado

2017-04-04

·

Atualizado

2019-10-09

·

CVE-2016-9358

CVSS v3.1

10

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Marel Food Processing Systems M3000 terminal (affected versions not specified) Marel Food Processing Systems M3210 terminal (affected versions not specified) Marel Food Processing Systems M3000 desktop software (affected versions not specified) Marel Food Processing Systems MAC4 controller (affected versions not specified) Marel Food Processing Systems SensorX23 X-ray machine (affected versions not specified) Marel Food Processing Systems SensorX25 X-ray machine (affected versions not specified) Marel Food Processing Systems MWS2 weighing system (affected versions not specified)
Description A Hard-Coded Passwords issue was discovered in various Marel Food Processing Systems, allowing an attacker to gain unauthorized administrative access to the devices. The affected systems include terminals, desktop software, controllers, X-ray machines, and a weighing system. The end user does not have the ability to change system passwords, and exploitation of this issue may allow a remote attacker to obtain administrative access.
Recommendations For Marel Food Processing Systems M3000 terminal, consider temporarily disabling the use of the terminal until a patch is available. For Marel Food Processing Systems M3210 terminal, consider temporarily disabling the use of the terminal until a patch is available. For Marel Food Processing Systems M3000 desktop software, consider restricting access to the software until a patch is available. For Marel Food Processing Systems MAC4 controller, consider temporarily disabling the use of the controller until a patch is available. For Marel Food Processing Systems SensorX23 X-ray machine and SensorX25 X-ray machine, consider restricting access to the machines until a patch is available. For Marel Food Processing Systems MWS2 weighing system, consider temporarily disabling the use of the system until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Using Hardcoded Credentials

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2017-02111
CVE-2016-9358

Produtos afetados

M3000 Desktop
M3000 Terminal
M3210 Terminal
Mac4 Controller
Mws2 Weighing System
Sensorx23 X-Ray Machine
Sensorx25 X-Ray Machine