Clorius Controls SCADA Information Disclosure

medium Nessus Network Monitor Plugin ID 6814

Synopsis

The remote SCADA device is affected by an information disclosure vulnerability

Description

NNM has detected a remote host obtaining the contents of 'html/info.htm' on the remote Clorius Controls ISC SCADA device. This page contains sensitive information such as the firmware version of the device, internal IP address and MAC address.

Solution

We are currently unaware of a solution for this problem. It is recommended that the device be isolated and protected from remote access by untrusted systems.

See Also

http://fm.iscclorius.com

http://www.nessus.org/u?2aa1d5e3

Plugin Details

Severity: Medium

ID: 6814

Family: SCADA

Published: 5/14/2013

Updated: 3/6/2019

Nessus ID: 66406

Risk Information

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 4.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS v3

Risk Factor: Medium

Base Score: 5.3

Temporal Score: 5.2

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Temporal Vector: CVSS:3.0/E:F/RL:U/RC:X

Vulnerability Information

Vulnerability Publication Date: 3/11/2013

Reference Information

BID: 58800