PT-2017-14535 · Abb · Ellipse
CVE-2017-16731
·
Publicado
2017-12-20
·
Atualizado
2023-05-16
CVSS v3.1
8.8
Alta
| Vetor | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
ABB Ellipse versions 8.3 through 8.9
Description
An issue with unprotected transport of credentials was found in the authentication of Ellipse to LDAP/AD using the LDAP protocol. This allows an attacker to exploit the issue by sniffing local network traffic, potentially discovering authentication credentials.
Recommendations
For ABB Ellipse versions 8.3 through 8.9, consider updating to a version released after December 2017 to resolve the issue. As a temporary workaround, restrict access to the local network to minimize the risk of exploitation.
Correção
Insufficiently Protected Credentials
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Ellipse