PT-2017-14535 · Abb · Ellipse

Published

2017-12-20

·

Updated

2023-05-16

·

CVE-2017-16731

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ABB Ellipse versions 8.3 through 8.9
Description An issue with unprotected transport of credentials was found in the authentication of Ellipse to LDAP/AD using the LDAP protocol. This allows an attacker to exploit the issue by sniffing local network traffic, potentially discovering authentication credentials.
Recommendations For ABB Ellipse versions 8.3 through 8.9, consider updating to a version released after December 2017 to resolve the issue. As a temporary workaround, restrict access to the local network to minimize the risk of exploitation.

Fix

Insufficiently Protected Credentials

Weakness Enumeration

Related Identifiers

CVE-2017-16731

Affected Products

Ellipse