PT-2020-19329 · Visam · Visam Vbase Web-Remote Module+2
Published
2020-04-03
·
Updated
2020-04-06
·
CVE-2020-7000
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
VISAM VBASE Editor version 11.5.0.2
VISAM VBASE Web-Remote Module
Description
The issue allows an unauthenticated attacker to discover the cryptographic key from the web server, gaining information about the login and the encryption/decryption mechanism. This could be exploited to bypass authentication of the HTML5 HMI web interface.
Recommendations
For VISAM VBASE Editor version 11.5.0.2, consider restricting access to the web server to minimize the risk of exploitation.
For VISAM VBASE Web-Remote Module, avoid using the module until a patch is available that secures the cryptographic key and authentication mechanism.
As a temporary workaround, consider disabling the HTML5 HMI web interface until a secure version is released.
Fix
Insecure Storage of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Html5 Hmi
Visam Vbase Editor
Visam Vbase Web-Remote Module