PT-2018-10473 · Myscada · Myscada Mypro
Emreovunc
·
Publicado
2018-05-20
·
Atualizado
2018-06-26
·
CVE-2018-11311
CVSS v3.1
9.1
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
mySCADA myPRO version 7
Description
The issue allows remote attackers to access the FTP server on port 2121, upload files, or list directories by using a hardcoded FTP username and password. The hardcoded credentials are
username set to 'myscada' and password set to 'Vikuk63' in the 'myscadagate.exe' file.Recommendations
For mySCADA myPRO version 7, consider changing the hardcoded FTP credentials to secure ones, and restrict access to the FTP server on port 2121 until a patch is available. As a temporary workaround, restrict the use of the 'myscadagate.exe' file to minimize the risk of exploitation.
Exploit
Correção
Using Hardcoded Credentials
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Myscada Mypro