Overview
GE Fanuc Proficy Information Portal allows authenticated users to upload arbitrary files. An attacker could upload an executable server-side script (e.g., an .asp shell on a Microsoft Internet Information Server platform) and execute arbitrary commands with the privileges of the web server.
Description
GE Fanuc Proficy Information Portal is a web-based systems reporting tool often used to consolidate and integrate online and process-based systems data between Supervisory Control And Data Acquisition (SCADA) systems and the corporate network. Proficy Information Portal supports an "Add WebSource" feature that allows authenticated users to upload arbitrary files to the server. An uploaded file can subsequently be executed by requesting it with a web browser. This vulnerability affects GE Fanuc Proficy Information Portal up to and including version 2.6. |
Impact
By uploading a file that can be executed by the web server (e.g., an .asp shell), a remote, authenticated attacker may be able to execute arbitrary code. The attacker could exploit this behavior to access SCADA networks. |
Solution
Patch |
Restrict Access
|
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
Acknowledgements
This vulnerability was reported by Eyal Udassin of C4 Security.
This document was written by Chris Taschner.
Other Information
CVE IDs: | CVE-2008-0175 |
Severity Metric: | 0.84 |
Date Public: | 2008-01-24 |
Date First Published: | 2008-01-25 |
Date Last Updated: | 2008-12-18 17:06 UTC |
Document Revision: | 45 |