Clorius Controls ISC SCADA Information Disclosure

medium Nessus Plugin ID 66406

Synopsis

The remote SCADA device is affected by an information disclosure vulnerability.

Description

Nessus was able to obtain the contents of '/html/info.htm' on the remote Clorius Contols ISC SCADA device. This page may contain sensitive information such as the firmware version of the device, internal IP address, and MAC address.

Solution

We are currently unaware of a solution for this problem. It is recommended that the device be isolated and protected from remote access by untrusted systems.

See Also

http://www.nessus.org/u?cbf809e7

Plugin Details

Severity: Medium

ID: 66406

File Name: scada_clorius_controls_info_disclosure.nbin

Version: 1.126

Type: remote

Family: SCADA

Published: 5/14/2013

Updated: 4/15/2024

Supported Sensors: Nessus

Risk Information

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 4.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Information

CPE: x-cpe:/h:clorius_controls:isc_scada

Required KB Items: www/scada_clorius_controls_isc_scada

Exploit Available: true

Exploit Ease: Exploits are available

Vulnerability Publication Date: 3/11/2013

Reference Information

BID: 58800

ICS-ALERT: 13-091-02