Clorius Controls SCADA Information Disclosure

Medium Nessus Network Monitor Plugin ID 6814

Synopsis

The remote SCADA device is affected by an information disclosure vulnerability

Description

PVS has detected a remote host obtaining the contents of 'html/info.htm' on the remote Clorius Controls ISC SCADA device. This page contains sensitive information such as the firmware version of the device, internal IP address and MAC address.

Solution

We are currently unaware of a solution for this problem. It is recommended that the device be isolated and protected from remote access by untrusted systems.

See Also

http://fm.iscclorius.com

http://www.nessus.org/u?2aa1d5e3

Plugin Details

Severity: Medium

ID: 6814

Family: SCADA

Published: 2013/05/14

Modified: 2016/01/21

Dependencies: 1442

Nessus ID: 66406

Risk Information

Risk Factor: Medium

CVSSv2

Base Score: 5

Temporal Score: 4.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

Temporal Vector: CVSS2#E:F/RL:U/RC:ND

CVSSv3

Base Score: 5.3

Temporal Score: 5.2

Vector: CVSS3#AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Temporal Vector: CVSS3#E:F/RL:U/RC:X

Vulnerability Information

Vulnerability Publication Date: 2013/03/11

Reference Information

BID: 58800