Clorius Controls ISC SCADA Information Disclosure

Medium Nessus Plugin ID 66406

Synopsis

The remote SCADA device is affected by an information disclosure vulnerability.

Description

Nessus was able to obtain the contents of '/html/info.htm' on the remote Clorius Contols ISC SCADA device. This page may contain sensitive information such as the firmware version of the device, internal IP address, and MAC address.

Solution

We are currently unaware of a solution for this problem. It is recommended that the device be isolated and protected from remote access by untrusted systems.

See Also

http://www.nessus.org/u?cbf809e7

Plugin Details

Severity: Medium

ID: 66406

File Name: scada_clorius_controls_info_disclosure.nbin

Version: 1.65

Type: remote

Family: SCADA

Published: 2013/05/14

Updated: 2020/02/26

Dependencies: 66405

Risk Information

Risk Factor: Medium

CVSS v2.0

Base Score: 5

Temporal Score: 4.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

Temporal Vector: CVSS2#E:F/RL:U/RC:ND

Vulnerability Information

CPE: x-cpe:/h:clorius_controls:isc_scada

Required KB Items: www/scada_clorius_controls_isc_scada

Exploit Available: true

Exploit Ease: Exploits are available

Vulnerability Publication Date: 2013/03/11

Reference Information

BID: 58800

ICS-ALERT: 13-091-02