Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-28c6-247x-r9mw

Опубликовано: 22 июн. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

A vulnerability has been identified in SIMATIC WinCC OA V3.16 (All versions in default configuration), SIMATIC WinCC OA V3.17 (All versions in non-default configuration), SIMATIC WinCC OA V3.18 (All versions in non-default configuration). Affected applications use client-side only authentication, when neither server-side authentication (SSA) nor Kerberos authentication is enabled. In this configuration, attackers could impersonate other users or exploit the client-server protocol without being authenticated.

A vulnerability has been identified in SIMATIC WinCC OA V3.16 (All versions in default configuration), SIMATIC WinCC OA V3.17 (All versions in non-default configuration), SIMATIC WinCC OA V3.18 (All versions in non-default configuration). Affected applications use client-side only authentication, when neither server-side authentication (SSA) nor Kerberos authentication is enabled. In this configuration, attackers could impersonate other users or exploit the client-server protocol without being authenticated.

EPSS

Процентиль: 59%
0.0039
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-287
CWE-603

Связанные уязвимости

CVSS3: 9.8
nvd
около 3 лет назад

A vulnerability has been identified in Cerberus DMS (All versions), Desigo CC (All versions), Desigo CC Compact (All versions), SIMATIC WinCC OA V3.16 (All versions in default configuration), SIMATIC WinCC OA V3.17 (All versions in non-default configuration), SIMATIC WinCC OA V3.18 (All versions in non-default configuration). Affected applications use client-side only authentication, when neither server-side authentication (SSA) nor Kerberos authentication is enabled. In this configuration, attackers could impersonate other users or exploit the client-server protocol without being authenticated.

CVSS3: 9.8
fstec
около 3 лет назад

Уязвимость SCADA-системы SIMATIC WinCC, связанная с возможностью использования аутентификации на стороне клиента, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 59%
0.0039
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-287
CWE-603