Honeywell EBI TEMA Remote Installer ActiveX Control Arbitrary File Download Vulnerability
BID:50078
Info
Honeywell EBI TEMA Remote Installer ActiveX Control Arbitrary File Download Vulnerability
| Bugtraq ID: | 50078 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 12 2011 12:00AM |
| Updated: | Jan 10 2013 05:40PM |
| Credit: | Billy Rios and Terry McCorkle |
| Vulnerable: |
Honeywell TEMA 5.3.1 Honeywell TEMA 5.3.0 Honeywell TEMA 5.2 Honeywell TEMA 4.9 Honeywell TEMA 4.8 Honeywell TEMA 4.10 Honeywell EBI R410.2 Honeywell EBI R410.1 Honeywell EBI R400.2 SP1 Honeywell EBI R310.1 |
| Not Vulnerable: | |
Discussion
Honeywell EBI TEMA Remote Installer ActiveX Control Arbitrary File Download Vulnerability
Honeywell EBI is prone to a vulnerability that exists in the TEMA installer and can allow malicious files to be downloaded and saved to arbitrary locations on an affected computer.
Successful exploits will allow attackers to download a malicious file onto a victims computer and execute arbitrary code within the context of the application that uses the ActiveX control (typically Internet Explorer).
This issue affects the following versions of EBI and corresponding versions of TEMA:
EBI R310.1 - TEMA 4.8
EBI R310.1 - TEMA 4.9
EBI R310.1 - TEMA 4.10
EBI R400.2 SP1 - TEMA 5.2
EBI R410.1 - TEMA 5.3.0
EBI R410.2 - TEMA 5.3.1.
Honeywell EBI is prone to a vulnerability that exists in the TEMA installer and can allow malicious files to be downloaded and saved to arbitrary locations on an affected computer.
Successful exploits will allow attackers to download a malicious file onto a victims computer and execute arbitrary code within the context of the application that uses the ActiveX control (typically Internet Explorer).
This issue affects the following versions of EBI and corresponding versions of TEMA:
EBI R310.1 - TEMA 4.8
EBI R310.1 - TEMA 4.9
EBI R310.1 - TEMA 4.10
EBI R400.2 SP1 - TEMA 5.2
EBI R410.1 - TEMA 5.3.0
EBI R410.2 - TEMA 5.3.1.
Exploit / POC
Honeywell EBI TEMA Remote Installer ActiveX Control Arbitrary File Download Vulnerability
Attackers can exploit this issue by tricking an unsuspecting victim into visiting a malicious webpage.
The following metasploit module is available:
Attackers can exploit this issue by tricking an unsuspecting victim into visiting a malicious webpage.
The following metasploit module is available:
Solution / Fix
Honeywell EBI TEMA Remote Installer ActiveX Control Arbitrary File Download Vulnerability
Solution:
The vendor released an update. Please contact the vendor more information on how to obtain and apply this update.
Solution:
The vendor released an update. Please contact the vendor more information on how to obtain and apply this update.
References
Honeywell EBI TEMA Remote Installer ActiveX Control Arbitrary File Download Vulnerability
References:
References:
- ICSA-11-285-01�??HONEYWELL TEMA REMOTE INSTALLER ACTIVEX VULNERABILITY (ICS-CERT)
- Microsoft Knowledge Base Article 240797 (Microsoft)
- Vendor Homepage (Honeywell)