EFACEC UC 500E

View CSAF

1. EXECUTIVE SUMMARY

  • CVSS v3 6.3
  • ATTENTION: Exploitable remotely/low attack complexity
  • Vendor: EFACEC
  • Equipment: UC 500
  • Vulnerabilities: Cleartext Transmission of Sensitive Information, Open Redirect, Exposure of Sensitive Information to an Unauthorized Actor, Improper Access Control

2. RISK EVALUATION

Successful exploitation of these vulnerabilities could allow an attacker to retrieve sensitive information, gain unauthorized access to the product, or redirect users to malicious websites.

3. TECHNICAL DETAILS

3.1 AFFECTED PRODUCTS

The following version of EFACEC UC 500E, a HMI, is affected:

  • UC 500E: version 10.1.0

3.2 Vulnerability Overview

3.2.1 CLEARTEXT TRANSMISSION OF SENSITIVE INFORMATION CWE-319

An attacker with network access could perform a man-in-the-middle (MitM) attack and capture sensitive information to gain unauthorized access to the application.

CVE-2023-50703 has been assigned to this vulnerability. A CVSS v3 base score of 6.3 has been calculated; the CVSS vector string is (AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N).

3.2.2 URL REDIRECTION TO UNTRUSTED SITE (‘OPEN REDIRECT’) CWE-601

An attacker could construct a URL within the application that causes a redirection to an arbitrary external domain and could be leveraged to facilitate phishing attacks against application users.

CVE-2023-50704 has been assigned to this vulnerability. A CVSS v3 base score of 4.3 has been calculated; the CVSS vector string is (This article has been indexed from All CISA Advisories

Read the original article:

EFACEC UC 500E