search menu icon-carat-right cmu-wordmark

CERT Coordination Center

UTC Fire & Security Master Clock contains hardcoded default administrator login credentials

Vulnerability Note VU#707254

Original Release Date: 2012-02-20 | Last Revised: 2012-07-23

Overview

UTC Fire & Security GE-MC100-NTP/GPS-ZB Master Clock have default administrator login credentials that can not be modified by an administrator.

Description

UTC Fire & Security GE-MC100-NTP/GPS-ZB Master Clock via Zigbee can sync up to 60,000 slave clocks located throughout a campus-area network. An administrator will typically log into the device by supplying credentials to a web-interface. These devices contain a consistent, hardcoded administrative username and password that cannot be changed by the administrator.

Impact

A remote, unauthenticated attacker can view and change system configuration files or other sensitive data.

Solution

We are currently unaware of a practical solution to this problem.

Restrict Access
Do not allow access to the web interface of the UTC Fire & Security GE-MC100-NTP/GPS-ZB Master Clock from untrusted networks.

Block Access to the Web Interface
Blocking access to port 80/tcp will prevent any user, even authorized administrators, from logging into the web-interface, but will not interfere with the UTC Fire & Security GE-MC100-NTP/GPS-ZB Master Clock slave clock syncing.

Vendor Information

707254
 

General Electric Affected

Notified:  January 09, 2012 Updated: February 06, 2012

Status

Affected

Vendor Statement

We have not received a statement from the vendor.

Vendor Information

We are not aware of further vendor information regarding this vulnerability.

UTC Fire & Security Affected

Notified:  January 12, 2012 Updated: February 06, 2012

Status

Affected

Vendor Statement

We have not received a statement from the vendor.

Vendor Information

We are not aware of further vendor information regarding this vulnerability.


CVSS Metrics

Group Score Vector
Base 5.3 AV:N/AC:/Au:N/C:C/I:C/A:C
Temporal 5 E:H/RL:W/RC:C
Environmental 1.3 CDP:/TD:L/CR:ND/IR:ND/AR:ND

References

Acknowledgements

Thanks to Temple Murphy for reporting this vulnerability.

This document was written by Michael Orlando.

Other Information

CVE IDs: CVE-2012-1288
Severity Metric: 34.20
Date Public: 2012-02-20
Date First Published: 2012-02-20
Date Last Updated: 2012-07-23 20:46 UTC
Document Revision: 24

Sponsored by CISA.