PT-2017-2831 · Marel Food Processing Systems · Mac4 Controller+6
Publicado
2017-04-04
·
Atualizado
2019-10-09
·
CVE-2016-9358
CVSS v3.1
10
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Marel Food Processing Systems M3000 terminal (affected versions not specified)
Marel Food Processing Systems M3210 terminal (affected versions not specified)
Marel Food Processing Systems M3000 desktop software (affected versions not specified)
Marel Food Processing Systems MAC4 controller (affected versions not specified)
Marel Food Processing Systems SensorX23 X-ray machine (affected versions not specified)
Marel Food Processing Systems SensorX25 X-ray machine (affected versions not specified)
Marel Food Processing Systems MWS2 weighing system (affected versions not specified)
Description
A Hard-Coded Passwords issue was discovered in various Marel Food Processing Systems, allowing an attacker to gain unauthorized administrative access to the devices. The affected systems include terminals, desktop software, controllers, X-ray machines, and a weighing system. The end user does not have the ability to change system passwords, and exploitation of this issue may allow a remote attacker to obtain administrative access.
Recommendations
For Marel Food Processing Systems M3000 terminal, consider temporarily disabling the use of the terminal until a patch is available.
For Marel Food Processing Systems M3210 terminal, consider temporarily disabling the use of the terminal until a patch is available.
For Marel Food Processing Systems M3000 desktop software, consider restricting access to the software until a patch is available.
For Marel Food Processing Systems MAC4 controller, consider temporarily disabling the use of the controller until a patch is available.
For Marel Food Processing Systems SensorX23 X-ray machine and SensorX25 X-ray machine, consider restricting access to the machines until a patch is available.
For Marel Food Processing Systems MWS2 weighing system, consider temporarily disabling the use of the system until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Using Hardcoded Credentials
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
M3000 Desktop
M3000 Terminal
M3210 Terminal
Mac4 Controller
Mws2 Weighing System
Sensorx23 X-Ray Machine
Sensorx25 X-Ray Machine