Siemens SIMATIC S7-300 Hardcoded Credentials Security Bypass Vulnerability
BID:48984
Info
Siemens SIMATIC S7-300 Hardcoded Credentials Security Bypass Vulnerability
| Bugtraq ID: | 48984 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 03 2011 12:00AM |
| Updated: | Aug 03 2011 12:00AM |
| Credit: | Dillion Beresford |
| Vulnerable: |
Siemens SIMATIC S7-300 0 |
| Not Vulnerable: | |
Discussion
Siemens SIMATIC S7-300 Hardcoded Credentials Security Bypass Vulnerability
Siemens SIMATIC S7-300 is prone to a security-bypass vulnerability caused by hard-coded credentials.
Successful attacks can allow a remote attacker to gain access to the vulnerable device.
Siemens SIMATIC S7-300 is prone to a security-bypass vulnerability caused by hard-coded credentials.
Successful attacks can allow a remote attacker to gain access to the vulnerable device.
Exploit / POC
Siemens SIMATIC S7-300 Hardcoded Credentials Security Bypass Vulnerability
An attacker can carry out this attack using readily available network utilities.
An attacker can carry out this attack using readily available network utilities.
Solution / Fix
Siemens SIMATIC S7-300 Hardcoded Credentials Security Bypass Vulnerability
Solution:
The vendor released an update. Please see the references for more information.
Solution:
The vendor released an update. Please see the references for more information.
References
Siemens SIMATIC S7-300 Hardcoded Credentials Security Bypass Vulnerability
References:
References: