RETIRED: IntelliCom NetBiter webSCADA Multiple Default Password Security Bypass Vulnerabilities
BID:37328
Info
RETIRED: IntelliCom NetBiter webSCADA Multiple Default Password Security Bypass Vulnerabilities
| Bugtraq ID: | 37328 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 14 2009 12:00AM |
| Updated: | Apr 06 2010 05:32PM |
| Credit: | Ruben Santamarta |
| Vulnerable: |
IntelliCom Innovation NetBiter webSCADA WS200 0 IntelliCom Innovation NetBiter webSCADA WS100 0 |
| Not Vulnerable: | |
Discussion
RETIRED: IntelliCom NetBiter webSCADA Multiple Default Password Security Bypass Vulnerabilities
IntelliCom NetBiter webSCADA devices are prone to multiple security-bypass vulnerabilities caused by hardcoded default passwords.
Successful exploits may allow attackers to gain privileged access to the device or network; other attacks may also be possible.
NOTE: This BID is being retired as it has been determined to not be a vulnerability. The default password and instructions on changing it are detailed in the product documentation.
IntelliCom NetBiter webSCADA devices are prone to multiple security-bypass vulnerabilities caused by hardcoded default passwords.
Successful exploits may allow attackers to gain privileged access to the device or network; other attacks may also be possible.
NOTE: This BID is being retired as it has been determined to not be a vulnerability. The default password and instructions on changing it are detailed in the product documentation.
Exploit / POC
RETIRED: IntelliCom NetBiter webSCADA Multiple Default Password Security Bypass Vulnerabilities
An attacker can carry out this attack using readily available network utilities.
An attacker can carry out this attack using readily available network utilities.
Solution / Fix
RETIRED: IntelliCom NetBiter webSCADA Multiple Default Password Security Bypass Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
RETIRED: IntelliCom NetBiter webSCADA Multiple Default Password Security Bypass Vulnerabilities
References:
References:
- IntelliCom Innovation Homepage (IntelliCom Innovation)
- IntelliCom NetBiter devices have default HICP passwords (US-CERT)
- NetBiter webSCADA Homepage (IntelliCom Innovation)
- Reverse Mode - Exposing HMS HICP Protocol + 0Day 'light' + SCADA_SHODAN (Ruben Santamarta)
- Exposing HMS HICP Protocol + Intellicom NetBiterConfig.exe Remote Buffer Overflo (Reversemode
) - IntelliCom Security Bulletin - ISFR-4404-0008: Default passwords in NetBiter fir (IntelliCom)