PT-2017-14535 · Abb · Ellipse
Published
2017-12-20
·
Updated
2023-05-16
·
CVE-2017-16731
CVSS v3.1
8.8
High
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
ABB Ellipse versions 8.3 through 8.9
Description
An issue with unprotected transport of credentials was found in the authentication of Ellipse to LDAP/AD using the LDAP protocol. This allows an attacker to exploit the issue by sniffing local network traffic, potentially discovering authentication credentials.
Recommendations
For ABB Ellipse versions 8.3 through 8.9, consider updating to a version released after December 2017 to resolve the issue. As a temporary workaround, restrict access to the local network to minimize the risk of exploitation.
Fix
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ellipse