IniNet Solutions SCADA Web Server CVE-2017-13995 Authentication Bypass Vulnerability
BID:100951
CVE-2017-13995 |Info
IniNet Solutions SCADA Web Server CVE-2017-13995 Authentication Bypass Vulnerability
| Bugtraq ID: | 100951 |
| Class: | Design Error |
| CVE: |
CVE-2017-13995 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 21 2017 12:00AM |
| Updated: | Sep 21 2017 12:00AM |
| Credit: | Matthias Niedermaier and Florian Fischer, both of Augsburg University of Applied Sciences. |
| Vulnerable: |
IniNet Solutions GmbH SCADA Web Server 2.02 IniNet Solutions GmbH SCADA Web Server 2.01 IniNet Solutions GmbH SCADA Web Server 2.0 |
| Not Vulnerable: |
IniNet Solutions GmbH SCADA Web Server 2.02.0100 |
Discussion
IniNet Solutions SCADA Web Server CVE-2017-13995 Authentication Bypass Vulnerability
IniNet Solutions SCADA Web Server is prone to an authentication-bypass vulnerability.
An attacker can exploit this issue to bypass the authentication mechanism and perform unauthorized actions. This may lead to further attacks.
IniNet Solutions SCADA Web Server prior to 2.02.0100 are vulnerable.
IniNet Solutions SCADA Web Server is prone to an authentication-bypass vulnerability.
An attacker can exploit this issue to bypass the authentication mechanism and perform unauthorized actions. This may lead to further attacks.
IniNet Solutions SCADA Web Server prior to 2.02.0100 are vulnerable.
Exploit / POC
IniNet Solutions SCADA Web Server CVE-2017-13995 Authentication Bypass Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution / Fix
IniNet Solutions SCADA Web Server CVE-2017-13995 Authentication Bypass Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
IniNet Solutions SCADA Web Server CVE-2017-13995 Authentication Bypass Vulnerability
References:
References:
- IniNet Solutions - Homepage (IniNet Solutions)
- Advisory (ICSA-17-264-04) iniNet Solutions GmbH SCADA Webserver (ICS-CERT)