Overview
GE Fanuc Proficy Information Portal can transmit authentication credentials in plain text. An attacker could monitor traffic, obtain valid credentials, and gain access to the portal.
Description
GE Fanuc Proficy Information Portal is a web-based systems reporting tool often used to consolidate and integrate online and process-based systems data between Supervisory Control And Data Acquisition (SCADA) systems and the corporate network. Authentication credentials for the portal may be sent in an insecure manner. During the login proceedure usernames are sent to the portal in plaintext and passwords are sent in Base64 encoded format. An attacker may be able to monitor network traffic and obtain credentaials to gain unauthorized access to the portal. This vulnerability affects GE Fanuc Proficy Information Portal up to and including version 2.6. |
Impact
An attacker who can intercept network traffic can obtain authentication credentials. |
Solution
|
|
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | 0 | AV:--/AC:--/Au:--/C:--/I:--/A:-- |
Temporal | 0 | E:ND/RL:ND/RC:ND |
Environmental | 0 | CDP:ND/TD:ND/CR:ND/IR:ND/AR:ND |
References
- http://www.securityfocus.com/archive/1/487075/30/0/threaded
- http://support.gefanuc.com/support/index?page=kbchannel&id=KB12459
- http://support.microsoft.com/kb/324274
- http://www.microsoft.com/technet/prodtechnol/WindowsServer2003/Library/IIS/36ea667e-c578-43b5-87fa-a2f174efb27a.mspx
- http://www.microsoft.com/technet/prodtechnol/windowsserver2003/library/iis/523ae943-5e6a-4200-9103-9808baa00157.mspx
- http://www.gefanuc.com/as_en/gefanuc/resource_center/hmi_scada/hmiscada_security.html
- http://java.sun.com/j2se/1.5.0/docs/guide/rmi/socketfactory/SSLInfo.html
- http://java.sun.com/j2se/1.5.0/docs/guide/rmi/socketfactory/index.html
- http://www.digitalmunition.com/hooked_on_fanucs.rb
- http://www.digitalmunition.com/rtipsniff.rb
- http://www.milw0rm.com/exploits/6921
Acknowledgements
This vulnerability was reported by Eyal Udassin of C4 Security.
This document was written by Chris Taschner.
Other Information
CVE IDs: | CVE-2008-0174 |
Severity Metric: | 0.17 |
Date Public: | 2008-01-24 |
Date First Published: | 2008-01-25 |
Date Last Updated: | 2008-11-13 16:35 UTC |
Document Revision: | 50 |