PT-2012-5556 · Invensys · Invensys Wonderware Intouch
Published
2012-12-18
·
Updated
2012-12-19
·
CVE-2012-4693
CVSS v2.0
1.9
Low
| Vector | AV:L/AC:M/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Invensys Wonderware InTouch versions 2012 R2 and earlier
Description
The issue concerns the use of a weak encryption algorithm for data stored in the Ps security.ini file. This weakness makes it easier for local users to discover passwords by reading this file.
Recommendations
For Invensys Wonderware InTouch versions 2012 R2 and earlier, consider restricting access to the Ps security.ini file to minimize the risk of password discovery until a stronger encryption algorithm is implemented.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Invensys Wonderware Intouch