PT-2017-2831 · Marel Food Processing Systems · Mac4 Controller+6
Published
2017-04-04
·
Updated
2019-10-09
·
CVE-2016-9358
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Marel Food Processing Systems M3000 terminal (affected versions not specified)
Marel Food Processing Systems M3210 terminal (affected versions not specified)
Marel Food Processing Systems M3000 desktop software (affected versions not specified)
Marel Food Processing Systems MAC4 controller (affected versions not specified)
Marel Food Processing Systems SensorX23 X-ray machine (affected versions not specified)
Marel Food Processing Systems SensorX25 X-ray machine (affected versions not specified)
Marel Food Processing Systems MWS2 weighing system (affected versions not specified)
Description
A Hard-Coded Passwords issue was discovered in various Marel Food Processing Systems, allowing an attacker to gain unauthorized administrative access to the devices. The affected systems include terminals, desktop software, controllers, X-ray machines, and a weighing system. The end user does not have the ability to change system passwords, and exploitation of this issue may allow a remote attacker to obtain administrative access.
Recommendations
For Marel Food Processing Systems M3000 terminal, consider temporarily disabling the use of the terminal until a patch is available.
For Marel Food Processing Systems M3210 terminal, consider temporarily disabling the use of the terminal until a patch is available.
For Marel Food Processing Systems M3000 desktop software, consider restricting access to the software until a patch is available.
For Marel Food Processing Systems MAC4 controller, consider temporarily disabling the use of the controller until a patch is available.
For Marel Food Processing Systems SensorX23 X-ray machine and SensorX25 X-ray machine, consider restricting access to the machines until a patch is available.
For Marel Food Processing Systems MWS2 weighing system, consider temporarily disabling the use of the system until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
M3000 Desktop
M3000 Terminal
M3210 Terminal
Mac4 Controller
Mws2 Weighing System
Sensorx23 X-Ray Machine
Sensorx25 X-Ray Machine