StruxureWare SCADA Expert ClearSCADA Weak Hashing Algorithm

medium Nessus Plugin ID 81049

Synopsis

The remote device is using a weak hashing algorithm.

Description

The self-signed certificate is signed with MD5, a depreciated and weak signing algorithm. An attacker can decrypt and decipher keys hashed with this algorithm.

Solution

Asset owners should obtain a signed web certificate from a certificate authority.

See Also

http://www.nessus.org/u?06f1cfbb

http://www.nessus.org/u?7d04c8d1

Plugin Details

Severity: Medium

ID: 81049

File Name: scada_clearscada_weak_hashing_algorithm.nbin

Version: 1.53

Type: remote

Family: SCADA

Published: 1/28/2015

Updated: 11/30/2022

Risk Information

VPR

Risk Factor: Low

Score: 3.6

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 3.7

Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Temporal Vector: E:U/RL:OF/RC:C

CVSS Score Source: CVE-2014-5413

Vulnerability Information

CPE: cpe:/a:schneider-electric:clearscada, cpe:/a:schneider-electric:scada_expert_clearscada

Required KB Items: SSL/Chain/WeakHash, SSL/Supported

Exploit Ease: No known exploits are available

Patch Publication Date: 10/6/2014

Vulnerability Publication Date: 8/29/2014

Reference Information

CVE: CVE-2014-5413

BID: 69842

ICSA: 14-259-01A