PT-2017-2831 · Marel Food Processing Systems · Mac4 Controller+6

Published

2017-04-04

·

Updated

2019-10-09

·

CVE-2016-9358

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Marel Food Processing Systems M3000 terminal (affected versions not specified) Marel Food Processing Systems M3210 terminal (affected versions not specified) Marel Food Processing Systems M3000 desktop software (affected versions not specified) Marel Food Processing Systems MAC4 controller (affected versions not specified) Marel Food Processing Systems SensorX23 X-ray machine (affected versions not specified) Marel Food Processing Systems SensorX25 X-ray machine (affected versions not specified) Marel Food Processing Systems MWS2 weighing system (affected versions not specified)
Description A Hard-Coded Passwords issue was discovered in various Marel Food Processing Systems, allowing an attacker to gain unauthorized administrative access to the devices. The affected systems include terminals, desktop software, controllers, X-ray machines, and a weighing system. The end user does not have the ability to change system passwords, and exploitation of this issue may allow a remote attacker to obtain administrative access.
Recommendations For Marel Food Processing Systems M3000 terminal, consider temporarily disabling the use of the terminal until a patch is available. For Marel Food Processing Systems M3210 terminal, consider temporarily disabling the use of the terminal until a patch is available. For Marel Food Processing Systems M3000 desktop software, consider restricting access to the software until a patch is available. For Marel Food Processing Systems MAC4 controller, consider temporarily disabling the use of the controller until a patch is available. For Marel Food Processing Systems SensorX23 X-ray machine and SensorX25 X-ray machine, consider restricting access to the machines until a patch is available. For Marel Food Processing Systems MWS2 weighing system, consider temporarily disabling the use of the system until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2017-02111
CVE-2016-9358

Affected Products

M3000 Desktop
M3000 Terminal
M3210 Terminal
Mac4 Controller
Mws2 Weighing System
Sensorx23 X-Ray Machine
Sensorx25 X-Ray Machine