Rewterz Threat Advisory – Advantech WebAccess Multiple Vulnerabilities
September 18, 2019Rewterz Threat Advisory – CVE-2019-13523 – ICS: Honeywell Performance IP Cameras and Performance NVRs Information Disclosure Vulnerability
September 18, 2019Rewterz Threat Advisory – Advantech WebAccess Multiple Vulnerabilities
September 18, 2019Rewterz Threat Advisory – CVE-2019-13523 – ICS: Honeywell Performance IP Cameras and Performance NVRs Information Disclosure Vulnerability
September 18, 2019Severity
High
Analysis Summary
CVE-2019-13918
The web interface has no means to prevent password guessing attacks. This vulnerability could be exploited by an attacker with network access to the vulnerable software, requiring no privileges and no user interaction. Exploitation could allow full access to the web interface.
CVE-2019-34623
Some pages that should only be accessible by a privileged user can also be accessed by a nonprivileged user. This vulnerability could be exploited by an attacker with network access and valid credentials for the web interface. No user interaction is required. Exploitation could allow an attacker to access information they should not be able to read. The information affected by this vulnerability does not include passwords.
CVE-2019-13920
Some parts of the web application are not protected against cross-site request forgery (CSRF) attacks. This vulnerability could be exploited by an attacker who is able to trigger requests of a logged-in user to the application. Exploitation could allow switching the connectivity state of a user or a device.
CVE-2019-13922
An attacker with administrative privileges can obtain the hash of a connected device’s password. The security vulnerability could be exploited by an attacker with network access to the SINEMA Remote Connect Server and administrative privileges.
Impact
- Privilege access
- Cross-site request forgery (CSRF)
- Exposure of sensitive information
Affected Vendors
Siemens
Affected Products
SINEMA Remote Connect Server versions prior to 2.0 SP1
Remediation
Siemens recommends users upgrade to Versions 2.0 SP1 or later for the affected products.
https://support.industry.siemens.com/cs/ww/en/view/109770899