QID 590852

Date Published: 2022-06-06

QID 590852: Siemens ProcessSuite and Invensys Intouch Poorly Encrypted Password File Vulnerability (ICSA-12-348-01)

A

QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of Siemens using registry "HKLM\SOFTWARE\Siemens"

An attacker with read permissions to the password file can decrypt it and obtain all usernames and passwords, allowing logon as a privileged user and take over the application.

  • CVSS V3 rated as Medium - 5.9 severity.
  • CVSS V2 rated as Low - 1.9 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section ICSA-12-348-01 for affected packages and patching details.

    Vendor References

    CVEs related to QID 590852

    Software Advisories
    Advisory ID Software Component Link
    ICSA-12-348-01 URL Logo www.us-cert.gov/ics/advisories/ICSA-12-348-01