Vulnerabilites related to echelon - smartserver_1
CVE-2018-8851 (GCVE-0-2018-8851)
Vulnerability from cvelistv5
Published
2018-07-24 17:00
Modified
2024-09-16 19:37
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-256 - UNPROTECTED STORAGE OF CREDENTIALS
Summary
Echelon SmartServer 1 all versions, SmartServer 2 all versions prior to release 4.11.007, i.LON 100 all versions, and i.LON 600 all versions. The devices store passwords in plaintext, which may allow an attacker with access to the configuration file to log into the SmartServer web user interface.
References
► | URL | Tags | |||
---|---|---|---|---|---|
|
Impacted products
Vendor | Product | Version | ||
---|---|---|---|---|
► | Echelon | SmartServer 1 |
Version: all versions |
|
{ "containers": { "adp": [ { "providerMetadata": { "dateUpdated": "2024-08-05T07:10:45.892Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "tags": [ "x_refsource_MISC", "x_transferred" ], "url": "https://ics-cert.us-cert.gov/advisories/ICSA-18-200-03" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "product": "SmartServer 1", "vendor": "Echelon", "versions": [ { "status": "affected", "version": "all versions" } ] }, { "product": "SmartServer 2", "vendor": "Echelon", "versions": [ { "status": "affected", "version": "all versions prior to release 4.11.007" } ] }, { "product": "i.LON 100", "vendor": "Echelon", "versions": [ { "status": "affected", "version": "all versions" } ] }, { "product": "i.LON 600", "vendor": "Echelon", "versions": [ { "status": "affected", "version": "all versions" } ] } ], "datePublic": "2018-07-19T00:00:00", "descriptions": [ { "lang": "en", "value": "Echelon SmartServer 1 all versions, SmartServer 2 all versions prior to release 4.11.007, i.LON 100 all versions, and i.LON 600 all versions. The devices store passwords in plaintext, which may allow an attacker with access to the configuration file to log into the SmartServer web user interface." } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-256", "description": "UNPROTECTED STORAGE OF CREDENTIALS CWE-256", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2018-07-24T16:57:01", "orgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6", "shortName": "icscert" }, "references": [ { "tags": [ "x_refsource_MISC" ], "url": "https://ics-cert.us-cert.gov/advisories/ICSA-18-200-03" } ], "x_legacyV4Record": { "CVE_data_meta": { "ASSIGNER": "ics-cert@hq.dhs.gov", "DATE_PUBLIC": "2018-07-19T00:00:00", "ID": "CVE-2018-8851", "STATE": "PUBLIC" }, "affects": { "vendor": { "vendor_data": [ { "product": { "product_data": [ { "product_name": "SmartServer 1", "version": { "version_data": [ { "version_value": "all versions" } ] } }, { "product_name": "SmartServer 2", "version": { "version_data": [ { "version_value": "all versions prior to release 4.11.007" } ] } }, { "product_name": "i.LON 100", "version": { "version_data": [ { "version_value": "all versions" } ] } }, { "product_name": "i.LON 600", "version": { "version_data": [ { "version_value": "all versions" } ] } } ] }, "vendor_name": "Echelon" } ] } }, "data_format": "MITRE", "data_type": "CVE", "data_version": "4.0", "description": { "description_data": [ { "lang": "eng", "value": "Echelon SmartServer 1 all versions, SmartServer 2 all versions prior to release 4.11.007, i.LON 100 all versions, and i.LON 600 all versions. The devices store passwords in plaintext, which may allow an attacker with access to the configuration file to log into the SmartServer web user interface." } ] }, "problemtype": { "problemtype_data": [ { "description": [ { "lang": "eng", "value": "UNPROTECTED STORAGE OF CREDENTIALS CWE-256" } ] } ] }, "references": { "reference_data": [ { "name": "https://ics-cert.us-cert.gov/advisories/ICSA-18-200-03", "refsource": "MISC", "url": "https://ics-cert.us-cert.gov/advisories/ICSA-18-200-03" } ] } } } }, "cveMetadata": { "assignerOrgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6", "assignerShortName": "icscert", "cveId": "CVE-2018-8851", "datePublished": "2018-07-24T17:00:00Z", "dateReserved": "2018-03-20T00:00:00", "dateUpdated": "2024-09-16T19:37:04.245Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2018-8855 (GCVE-0-2018-8855)
Vulnerability from cvelistv5
Published
2018-07-24 17:00
Modified
2024-09-17 01:10
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-319 - CLEARTEXT TRANSMISSION OF SENSITIVE INFORMATION
Summary
Echelon SmartServer 1 all versions, SmartServer 2 all versions prior to release 4.11.007, i.LON 100 all versions, and i.LON 600 all versions. The devices allow unencrypted Web connections by default, and devices can receive configuration and firmware updates by unsecure FTP.
References
► | URL | Tags | |||
---|---|---|---|---|---|
|
Impacted products
Vendor | Product | Version | ||
---|---|---|---|---|
► | Echelon | SmartServer 1 |
Version: all versions |
|
{ "containers": { "adp": [ { "providerMetadata": { "dateUpdated": "2024-08-05T07:10:46.267Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "tags": [ "x_refsource_MISC", "x_transferred" ], "url": "https://ics-cert.us-cert.gov/advisories/ICSA-18-200-03" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "product": "SmartServer 1", "vendor": "Echelon", "versions": [ { "status": "affected", "version": "all versions" } ] }, { "product": "SmartServer 2", "vendor": "Echelon", "versions": [ { "status": "affected", "version": "all versions prior to release 4.11.007" } ] }, { "product": "i.LON 100", "vendor": "Echelon", "versions": [ { "status": "affected", "version": "all versions" } ] }, { "product": "i.LON 600", "vendor": "Echelon", "versions": [ { "status": "affected", "version": "all versions" } ] } ], "datePublic": "2018-07-19T00:00:00", "descriptions": [ { "lang": "en", "value": "Echelon SmartServer 1 all versions, SmartServer 2 all versions prior to release 4.11.007, i.LON 100 all versions, and i.LON 600 all versions. The devices allow unencrypted Web connections by default, and devices can receive configuration and firmware updates by unsecure FTP." } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-319", "description": "CLEARTEXT TRANSMISSION OF SENSITIVE INFORMATION CWE-319", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2018-07-24T16:57:01", "orgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6", "shortName": "icscert" }, "references": [ { "tags": [ "x_refsource_MISC" ], "url": "https://ics-cert.us-cert.gov/advisories/ICSA-18-200-03" } ], "x_legacyV4Record": { "CVE_data_meta": { "ASSIGNER": "ics-cert@hq.dhs.gov", "DATE_PUBLIC": "2018-07-19T00:00:00", "ID": "CVE-2018-8855", "STATE": "PUBLIC" }, "affects": { "vendor": { "vendor_data": [ { "product": { "product_data": [ { "product_name": "SmartServer 1", "version": { "version_data": [ { "version_value": "all versions" } ] } }, { "product_name": "SmartServer 2", "version": { "version_data": [ { "version_value": "all versions prior to release 4.11.007" } ] } }, { "product_name": "i.LON 100", "version": { "version_data": [ { "version_value": "all versions" } ] } }, { "product_name": "i.LON 600", "version": { "version_data": [ { "version_value": "all versions" } ] } } ] }, "vendor_name": "Echelon" } ] } }, "data_format": "MITRE", "data_type": "CVE", "data_version": "4.0", "description": { "description_data": [ { "lang": "eng", "value": "Echelon SmartServer 1 all versions, SmartServer 2 all versions prior to release 4.11.007, i.LON 100 all versions, and i.LON 600 all versions. The devices allow unencrypted Web connections by default, and devices can receive configuration and firmware updates by unsecure FTP." } ] }, "problemtype": { "problemtype_data": [ { "description": [ { "lang": "eng", "value": "CLEARTEXT TRANSMISSION OF SENSITIVE INFORMATION CWE-319" } ] } ] }, "references": { "reference_data": [ { "name": "https://ics-cert.us-cert.gov/advisories/ICSA-18-200-03", "refsource": "MISC", "url": "https://ics-cert.us-cert.gov/advisories/ICSA-18-200-03" } ] } } } }, "cveMetadata": { "assignerOrgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6", "assignerShortName": "icscert", "cveId": "CVE-2018-8855", "datePublished": "2018-07-24T17:00:00Z", "dateReserved": "2018-03-20T00:00:00", "dateUpdated": "2024-09-17T01:10:42.995Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2018-10627 (GCVE-0-2018-10627)
Vulnerability from cvelistv5
Published
2018-07-24 17:00
Modified
2024-09-16 21:04
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-200 - INFORMATION EXPOSURE
Summary
Echelon SmartServer 1 all versions, SmartServer 2 all versions prior to release 4.11.007, i.LON 100 all versions, and i.LON 600 all versions. An attacker can use the SOAP API to retrieve and change sensitive configuration items such as the usernames and passwords for the Web and FTP servers. This vulnerability does not affect the i.LON 600 product.
References
► | URL | Tags | |||
---|---|---|---|---|---|
|
Impacted products
Vendor | Product | Version | ||
---|---|---|---|---|
► | Echelon | SmartServer 1 |
Version: all versions |
|
{ "containers": { "adp": [ { "providerMetadata": { "dateUpdated": "2024-08-05T07:46:46.161Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "tags": [ "x_refsource_MISC", "x_transferred" ], "url": "https://ics-cert.us-cert.gov/advisories/ICSA-18-200-03" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "product": "SmartServer 1", "vendor": "Echelon", "versions": [ { "status": "affected", "version": "all versions" } ] }, { "product": "SmartServer 2", "vendor": "Echelon", "versions": [ { "status": "affected", "version": "all versions prior to release 4.11.007" } ] }, { "product": "i.LON 100", "vendor": "Echelon", "versions": [ { "status": "affected", "version": "all versions" } ] }, { "product": "i.LON 600", "vendor": "Echelon", "versions": [ { "status": "affected", "version": "all versions" } ] } ], "datePublic": "2018-07-19T00:00:00", "descriptions": [ { "lang": "en", "value": "Echelon SmartServer 1 all versions, SmartServer 2 all versions prior to release 4.11.007, i.LON 100 all versions, and i.LON 600 all versions. An attacker can use the SOAP API to retrieve and change sensitive configuration items such as the usernames and passwords for the Web and FTP servers. This vulnerability does not affect the i.LON 600 product." } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-200", "description": "INFORMATION EXPOSURE CWE-200", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2018-07-24T16:57:01", "orgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6", "shortName": "icscert" }, "references": [ { "tags": [ "x_refsource_MISC" ], "url": "https://ics-cert.us-cert.gov/advisories/ICSA-18-200-03" } ], "x_legacyV4Record": { "CVE_data_meta": { "ASSIGNER": "ics-cert@hq.dhs.gov", "DATE_PUBLIC": "2018-07-19T00:00:00", "ID": "CVE-2018-10627", "STATE": "PUBLIC" }, "affects": { "vendor": { "vendor_data": [ { "product": { "product_data": [ { "product_name": "SmartServer 1", "version": { "version_data": [ { "version_value": "all versions" } ] } }, { "product_name": "SmartServer 2", "version": { "version_data": [ { "version_value": "all versions prior to release 4.11.007" } ] } }, { "product_name": "i.LON 100", "version": { "version_data": [ { "version_value": "all versions" } ] } }, { "product_name": "i.LON 600", "version": { "version_data": [ { "version_value": "all versions" } ] } } ] }, "vendor_name": "Echelon" } ] } }, "data_format": "MITRE", "data_type": "CVE", "data_version": "4.0", "description": { "description_data": [ { "lang": "eng", "value": "Echelon SmartServer 1 all versions, SmartServer 2 all versions prior to release 4.11.007, i.LON 100 all versions, and i.LON 600 all versions. An attacker can use the SOAP API to retrieve and change sensitive configuration items such as the usernames and passwords for the Web and FTP servers. This vulnerability does not affect the i.LON 600 product." } ] }, "problemtype": { "problemtype_data": [ { "description": [ { "lang": "eng", "value": "INFORMATION EXPOSURE CWE-200" } ] } ] }, "references": { "reference_data": [ { "name": "https://ics-cert.us-cert.gov/advisories/ICSA-18-200-03", "refsource": "MISC", "url": "https://ics-cert.us-cert.gov/advisories/ICSA-18-200-03" } ] } } } }, "cveMetadata": { "assignerOrgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6", "assignerShortName": "icscert", "cveId": "CVE-2018-10627", "datePublished": "2018-07-24T17:00:00Z", "dateReserved": "2018-05-01T00:00:00", "dateUpdated": "2024-09-16T21:04:33.686Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
CVE-2018-8859 (GCVE-0-2018-8859)
Vulnerability from cvelistv5
Published
2018-07-24 17:00
Modified
2024-09-17 03:48
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- CWE-288 - AUTHENTICATION BYPASS USING AN ALTERNATE PATH OR CHANNEL
Summary
Echelon SmartServer 1 all versions, SmartServer 2 all versions prior to release 4.11.007, i.LON 100 all versions, and i.LON 600 all versions. An attacker can bypass the required authentication specified in the security configuration file by including extra characters in the directory name when specifying the directory to be accessed. This vulnerability does not affect the i.LON 600 product.
References
► | URL | Tags | |||
---|---|---|---|---|---|
|
Impacted products
Vendor | Product | Version | ||
---|---|---|---|---|
► | Echelon | SmartServer 1 |
Version: all versions |
|
{ "containers": { "adp": [ { "providerMetadata": { "dateUpdated": "2024-08-05T07:10:46.232Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "tags": [ "x_refsource_MISC", "x_transferred" ], "url": "https://ics-cert.us-cert.gov/advisories/ICSA-18-200-03" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "product": "SmartServer 1", "vendor": "Echelon", "versions": [ { "status": "affected", "version": "all versions" } ] }, { "product": "SmartServer 2", "vendor": "Echelon", "versions": [ { "status": "affected", "version": "all versions prior to release 4.11.007" } ] }, { "product": "i.LON 100", "vendor": "Echelon", "versions": [ { "status": "affected", "version": "all versions" } ] }, { "product": "i.LON 600", "vendor": "Echelon", "versions": [ { "status": "affected", "version": "all versions" } ] } ], "datePublic": "2018-07-19T00:00:00", "descriptions": [ { "lang": "en", "value": "Echelon SmartServer 1 all versions, SmartServer 2 all versions prior to release 4.11.007, i.LON 100 all versions, and i.LON 600 all versions. An attacker can bypass the required authentication specified in the security configuration file by including extra characters in the directory name when specifying the directory to be accessed. This vulnerability does not affect the i.LON 600 product." } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-288", "description": "AUTHENTICATION BYPASS USING AN ALTERNATE PATH OR CHANNEL CWE-288", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2018-07-24T16:57:01", "orgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6", "shortName": "icscert" }, "references": [ { "tags": [ "x_refsource_MISC" ], "url": "https://ics-cert.us-cert.gov/advisories/ICSA-18-200-03" } ], "x_legacyV4Record": { "CVE_data_meta": { "ASSIGNER": "ics-cert@hq.dhs.gov", "DATE_PUBLIC": "2018-07-19T00:00:00", "ID": "CVE-2018-8859", "STATE": "PUBLIC" }, "affects": { "vendor": { "vendor_data": [ { "product": { "product_data": [ { "product_name": "SmartServer 1", "version": { "version_data": [ { "version_value": "all versions" } ] } }, { "product_name": "SmartServer 2", "version": { "version_data": [ { "version_value": "all versions prior to release 4.11.007" } ] } }, { "product_name": "i.LON 100", "version": { "version_data": [ { "version_value": "all versions" } ] } }, { "product_name": "i.LON 600", "version": { "version_data": [ { "version_value": "all versions" } ] } } ] }, "vendor_name": "Echelon" } ] } }, "data_format": "MITRE", "data_type": "CVE", "data_version": "4.0", "description": { "description_data": [ { "lang": "eng", "value": "Echelon SmartServer 1 all versions, SmartServer 2 all versions prior to release 4.11.007, i.LON 100 all versions, and i.LON 600 all versions. An attacker can bypass the required authentication specified in the security configuration file by including extra characters in the directory name when specifying the directory to be accessed. This vulnerability does not affect the i.LON 600 product." } ] }, "problemtype": { "problemtype_data": [ { "description": [ { "lang": "eng", "value": "AUTHENTICATION BYPASS USING AN ALTERNATE PATH OR CHANNEL CWE-288" } ] } ] }, "references": { "reference_data": [ { "name": "https://ics-cert.us-cert.gov/advisories/ICSA-18-200-03", "refsource": "MISC", "url": "https://ics-cert.us-cert.gov/advisories/ICSA-18-200-03" } ] } } } }, "cveMetadata": { "assignerOrgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6", "assignerShortName": "icscert", "cveId": "CVE-2018-8859", "datePublished": "2018-07-24T17:00:00Z", "dateReserved": "2018-03-20T00:00:00", "dateUpdated": "2024-09-17T03:48:36.377Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
Vulnerability from fkie_nvd
Published
2018-07-24 17:29
Modified
2024-11-21 04:14
Severity ?
Summary
Echelon SmartServer 1 all versions, SmartServer 2 all versions prior to release 4.11.007, i.LON 100 all versions, and i.LON 600 all versions. The devices allow unencrypted Web connections by default, and devices can receive configuration and firmware updates by unsecure FTP.
References
▶ | URL | Tags | |
---|---|---|---|
ics-cert@hq.dhs.gov | https://ics-cert.us-cert.gov/advisories/ICSA-18-200-03 | Third Party Advisory, US Government Resource | |
af854a3a-2127-422b-91ae-364da2661108 | https://ics-cert.us-cert.gov/advisories/ICSA-18-200-03 | Third Party Advisory, US Government Resource |
Impacted products
Vendor | Product | Version | |
---|---|---|---|
echelon | smartserver_1_firmware | - | |
echelon | smartserver_1 | - | |
echelon | smartserver_2_firmware | * | |
echelon | smartserver_2 | - | |
echelon | i.lon_100_firmware | - | |
echelon | i.lon_100 | - | |
echelon | i.lon_600_firmware | - | |
echelon | i.lon_600 | - |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:o:echelon:smartserver_1_firmware:-:*:*:*:*:*:*:*", "matchCriteriaId": "82A8FFC2-7191-42FE-8F71-77DE83945FFA", "vulnerable": true } ], "negate": false, "operator": "OR" }, { "cpeMatch": [ { "criteria": "cpe:2.3:h:echelon:smartserver_1:-:*:*:*:*:*:*:*", "matchCriteriaId": "9D78AEC2-D6E0-42EE-AEF4-5AEBA6B29611", "vulnerable": false } ], "negate": false, "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:o:echelon:smartserver_2_firmware:*:*:*:*:*:*:*:*", "matchCriteriaId": "83547993-8A11-4A60-9CBE-3CD006272A1C", "versionEndExcluding": "4.11.007", "vulnerable": true } ], "negate": false, "operator": "OR" }, { "cpeMatch": [ { "criteria": "cpe:2.3:h:echelon:smartserver_2:-:*:*:*:*:*:*:*", "matchCriteriaId": "418DEBAC-57D5-4BA8-806B-3DC235F1B625", "vulnerable": false } ], "negate": false, "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:o:echelon:i.lon_100_firmware:-:*:*:*:*:*:*:*", "matchCriteriaId": "4DC38B32-715F-4ECA-AA60-15BE5EEB0DDE", "vulnerable": true } ], "negate": false, "operator": "OR" }, { "cpeMatch": [ { "criteria": "cpe:2.3:h:echelon:i.lon_100:-:*:*:*:*:*:*:*", "matchCriteriaId": "D195E8CF-A5E2-4799-A0EF-189A825BB3AF", "vulnerable": false } ], "negate": false, "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:o:echelon:i.lon_600_firmware:-:*:*:*:*:*:*:*", "matchCriteriaId": "D1F3F845-E167-48A6-B159-39634D4D5DEB", "vulnerable": true } ], "negate": false, "operator": "OR" }, { "cpeMatch": [ { "criteria": "cpe:2.3:h:echelon:i.lon_600:-:*:*:*:*:*:*:*", "matchCriteriaId": "129D5CFF-EE75-4AED-89B1-DD947359DFFE", "vulnerable": false } ], "negate": false, "operator": "OR" } ], "operator": "AND" } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "Echelon SmartServer 1 all versions, SmartServer 2 all versions prior to release 4.11.007, i.LON 100 all versions, and i.LON 600 all versions. The devices allow unencrypted Web connections by default, and devices can receive configuration and firmware updates by unsecure FTP." }, { "lang": "es", "value": "Echelon SmartServer 1 en todas las versiones, SmartServer 2 en todas las versiones anteriores a 4.11.007, i.LON 100 en todas las versiones y i.LON 600 en todas las versiones. Los dispositivos permiten las conexiones web sin cifrar por defecto y, adem\u00e1s, pueden recibir actualizaciones de configuraci\u00f3n y firmware a trav\u00e9s de FTP inseguro." } ], "id": "CVE-2018-8855", "lastModified": "2024-11-21T04:14:27.677", "metrics": { "cvssMetricV2": [ { "acInsufInfo": false, "baseSeverity": "HIGH", "cvssData": { "accessComplexity": "LOW", "accessVector": "NETWORK", "authentication": "NONE", "availabilityImpact": "PARTIAL", "baseScore": 7.5, "confidentialityImpact": "PARTIAL", "integrityImpact": "PARTIAL", "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P", "version": "2.0" }, "exploitabilityScore": 10.0, "impactScore": 6.4, "obtainAllPrivilege": false, "obtainOtherPrivilege": false, "obtainUserPrivilege": false, "source": "nvd@nist.gov", "type": "Primary", "userInteractionRequired": false } ], "cvssMetricV30": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 9.8, "baseSeverity": "CRITICAL", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "version": "3.0" }, "exploitabilityScore": 3.9, "impactScore": 5.9, "source": "nvd@nist.gov", "type": "Primary" } ] }, "published": "2018-07-24T17:29:00.400", "references": [ { "source": "ics-cert@hq.dhs.gov", "tags": [ "Third Party Advisory", "US Government Resource" ], "url": "https://ics-cert.us-cert.gov/advisories/ICSA-18-200-03" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Third Party Advisory", "US Government Resource" ], "url": "https://ics-cert.us-cert.gov/advisories/ICSA-18-200-03" } ], "sourceIdentifier": "ics-cert@hq.dhs.gov", "vulnStatus": "Modified", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-319" } ], "source": "ics-cert@hq.dhs.gov", "type": "Secondary" }, { "description": [ { "lang": "en", "value": "CWE-319" } ], "source": "nvd@nist.gov", "type": "Primary" } ] }
Vulnerability from fkie_nvd
Published
2018-07-24 17:29
Modified
2024-11-21 04:14
Severity ?
Summary
Echelon SmartServer 1 all versions, SmartServer 2 all versions prior to release 4.11.007, i.LON 100 all versions, and i.LON 600 all versions. An attacker can bypass the required authentication specified in the security configuration file by including extra characters in the directory name when specifying the directory to be accessed. This vulnerability does not affect the i.LON 600 product.
References
▶ | URL | Tags | |
---|---|---|---|
ics-cert@hq.dhs.gov | https://ics-cert.us-cert.gov/advisories/ICSA-18-200-03 | Third Party Advisory, US Government Resource | |
af854a3a-2127-422b-91ae-364da2661108 | https://ics-cert.us-cert.gov/advisories/ICSA-18-200-03 | Third Party Advisory, US Government Resource |
Impacted products
Vendor | Product | Version | |
---|---|---|---|
echelon | smartserver_1_firmware | - | |
echelon | smartserver_1 | - | |
echelon | smartserver_2_firmware | * | |
echelon | smartserver_2 | - | |
echelon | i.lon_100_firmware | - | |
echelon | i.lon_100 | - | |
echelon | i.lon_600_firmware | - | |
echelon | i.lon_600 | - |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:o:echelon:smartserver_1_firmware:-:*:*:*:*:*:*:*", "matchCriteriaId": "82A8FFC2-7191-42FE-8F71-77DE83945FFA", "vulnerable": true } ], "negate": false, "operator": "OR" }, { "cpeMatch": [ { "criteria": "cpe:2.3:h:echelon:smartserver_1:-:*:*:*:*:*:*:*", "matchCriteriaId": "9D78AEC2-D6E0-42EE-AEF4-5AEBA6B29611", "vulnerable": false } ], "negate": false, "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:o:echelon:smartserver_2_firmware:*:*:*:*:*:*:*:*", "matchCriteriaId": "83547993-8A11-4A60-9CBE-3CD006272A1C", "versionEndExcluding": "4.11.007", "vulnerable": true } ], "negate": false, "operator": "OR" }, { "cpeMatch": [ { "criteria": "cpe:2.3:h:echelon:smartserver_2:-:*:*:*:*:*:*:*", "matchCriteriaId": "418DEBAC-57D5-4BA8-806B-3DC235F1B625", "vulnerable": false } ], "negate": false, "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:o:echelon:i.lon_100_firmware:-:*:*:*:*:*:*:*", "matchCriteriaId": "4DC38B32-715F-4ECA-AA60-15BE5EEB0DDE", "vulnerable": true } ], "negate": false, "operator": "OR" }, { "cpeMatch": [ { "criteria": "cpe:2.3:h:echelon:i.lon_100:-:*:*:*:*:*:*:*", "matchCriteriaId": "D195E8CF-A5E2-4799-A0EF-189A825BB3AF", "vulnerable": false } ], "negate": false, "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:o:echelon:i.lon_600_firmware:-:*:*:*:*:*:*:*", "matchCriteriaId": "D1F3F845-E167-48A6-B159-39634D4D5DEB", "vulnerable": true } ], "negate": false, "operator": "OR" }, { "cpeMatch": [ { "criteria": "cpe:2.3:h:echelon:i.lon_600:-:*:*:*:*:*:*:*", "matchCriteriaId": "129D5CFF-EE75-4AED-89B1-DD947359DFFE", "vulnerable": false } ], "negate": false, "operator": "OR" } ], "operator": "AND" } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "Echelon SmartServer 1 all versions, SmartServer 2 all versions prior to release 4.11.007, i.LON 100 all versions, and i.LON 600 all versions. An attacker can bypass the required authentication specified in the security configuration file by including extra characters in the directory name when specifying the directory to be accessed. This vulnerability does not affect the i.LON 600 product." }, { "lang": "es", "value": "Echelon SmartServer 1 en todas las versiones, SmartServer 2 en todas las versiones anteriores a 4.11.007, i.LON 100 en todas las versiones y i.LON 600 en todas las versiones. Un atacante puede omitir la autenticaci\u00f3n requerida especificada en el archivo de configuraci\u00f3n de seguridad incluyendo caracteres urgentes en el nombre de directorio al especificar el directorio al que ser va a acceder. Esta vulnerabilidad no afecta al producto i.LON 600." } ], "id": "CVE-2018-8859", "lastModified": "2024-11-21T04:14:28.190", "metrics": { "cvssMetricV2": [ { "acInsufInfo": false, "baseSeverity": "HIGH", "cvssData": { "accessComplexity": "LOW", "accessVector": "NETWORK", "authentication": "NONE", "availabilityImpact": "PARTIAL", "baseScore": 7.5, "confidentialityImpact": "PARTIAL", "integrityImpact": "PARTIAL", "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P", "version": "2.0" }, "exploitabilityScore": 10.0, "impactScore": 6.4, "obtainAllPrivilege": false, "obtainOtherPrivilege": false, "obtainUserPrivilege": false, "source": "nvd@nist.gov", "type": "Primary", "userInteractionRequired": false } ], "cvssMetricV30": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 9.8, "baseSeverity": "CRITICAL", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "version": "3.0" }, "exploitabilityScore": 3.9, "impactScore": 5.9, "source": "nvd@nist.gov", "type": "Primary" } ] }, "published": "2018-07-24T17:29:00.430", "references": [ { "source": "ics-cert@hq.dhs.gov", "tags": [ "Third Party Advisory", "US Government Resource" ], "url": "https://ics-cert.us-cert.gov/advisories/ICSA-18-200-03" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Third Party Advisory", "US Government Resource" ], "url": "https://ics-cert.us-cert.gov/advisories/ICSA-18-200-03" } ], "sourceIdentifier": "ics-cert@hq.dhs.gov", "vulnStatus": "Modified", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-288" } ], "source": "ics-cert@hq.dhs.gov", "type": "Secondary" }, { "description": [ { "lang": "en", "value": "CWE-287" } ], "source": "nvd@nist.gov", "type": "Primary" } ] }
Vulnerability from fkie_nvd
Published
2018-07-24 17:29
Modified
2024-11-21 03:41
Severity ?
Summary
Echelon SmartServer 1 all versions, SmartServer 2 all versions prior to release 4.11.007, i.LON 100 all versions, and i.LON 600 all versions. An attacker can use the SOAP API to retrieve and change sensitive configuration items such as the usernames and passwords for the Web and FTP servers. This vulnerability does not affect the i.LON 600 product.
References
▶ | URL | Tags | |
---|---|---|---|
ics-cert@hq.dhs.gov | https://ics-cert.us-cert.gov/advisories/ICSA-18-200-03 | Third Party Advisory, US Government Resource | |
af854a3a-2127-422b-91ae-364da2661108 | https://ics-cert.us-cert.gov/advisories/ICSA-18-200-03 | Third Party Advisory, US Government Resource |
Impacted products
Vendor | Product | Version | |
---|---|---|---|
echelon | smartserver_1_firmware | * | |
echelon | smartserver_1 | - | |
echelon | smartserver_2_firmware | * | |
echelon | smartserver_2 | - | |
echelon | i.lon_100_firmware | * | |
echelon | i.lon_100 | - |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:o:echelon:smartserver_1_firmware:*:*:*:*:*:*:*:*", "matchCriteriaId": "096B893D-BCDF-4788-81F4-301FE9E074F3", "vulnerable": true } ], "negate": false, "operator": "OR" }, { "cpeMatch": [ { "criteria": "cpe:2.3:h:echelon:smartserver_1:-:*:*:*:*:*:*:*", "matchCriteriaId": "9D78AEC2-D6E0-42EE-AEF4-5AEBA6B29611", "vulnerable": false } ], "negate": false, "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:o:echelon:smartserver_2_firmware:*:*:*:*:*:*:*:*", "matchCriteriaId": "83547993-8A11-4A60-9CBE-3CD006272A1C", "versionEndExcluding": "4.11.007", "vulnerable": true } ], "negate": false, "operator": "OR" }, { "cpeMatch": [ { "criteria": "cpe:2.3:h:echelon:smartserver_2:-:*:*:*:*:*:*:*", "matchCriteriaId": "418DEBAC-57D5-4BA8-806B-3DC235F1B625", "vulnerable": false } ], "negate": false, "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:o:echelon:i.lon_100_firmware:*:*:*:*:*:*:*:*", "matchCriteriaId": "124BE3F4-8E5F-46F7-9545-6D4E31B5A275", "vulnerable": true } ], "negate": false, "operator": "OR" }, { "cpeMatch": [ { "criteria": "cpe:2.3:h:echelon:i.lon_100:-:*:*:*:*:*:*:*", "matchCriteriaId": "D195E8CF-A5E2-4799-A0EF-189A825BB3AF", "vulnerable": false } ], "negate": false, "operator": "OR" } ], "operator": "AND" } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "Echelon SmartServer 1 all versions, SmartServer 2 all versions prior to release 4.11.007, i.LON 100 all versions, and i.LON 600 all versions. An attacker can use the SOAP API to retrieve and change sensitive configuration items such as the usernames and passwords for the Web and FTP servers. This vulnerability does not affect the i.LON 600 product." }, { "lang": "es", "value": "Echelon SmartServer 1 en todas las versiones, SmartServer 2 en todas las versiones anteriores a 4.11.007, i.LON 100 en todas las versiones y i.LON 600 en todas las versiones. Un atacante puede emplear la API SOAP para recuperar y cambiar elementos de configuraci\u00f3n sensibles como los nombres de usuario y las contrase\u00f1as para los servidores web y FTP. Esta vulnerabilidad no afecta al producto i.LON 600." } ], "id": "CVE-2018-10627", "lastModified": "2024-11-21T03:41:41.593", "metrics": { "cvssMetricV2": [ { "acInsufInfo": false, "baseSeverity": "MEDIUM", "cvssData": { "accessComplexity": "LOW", "accessVector": "NETWORK", "authentication": "NONE", "availabilityImpact": "NONE", "baseScore": 6.4, "confidentialityImpact": "PARTIAL", "integrityImpact": "PARTIAL", "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:N", "version": "2.0" }, "exploitabilityScore": 10.0, "impactScore": 4.9, "obtainAllPrivilege": false, "obtainOtherPrivilege": false, "obtainUserPrivilege": false, "source": "nvd@nist.gov", "type": "Primary", "userInteractionRequired": false } ], "cvssMetricV30": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 9.8, "baseSeverity": "CRITICAL", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "version": "3.0" }, "exploitabilityScore": 3.9, "impactScore": 5.9, "source": "nvd@nist.gov", "type": "Primary" } ] }, "published": "2018-07-24T17:29:00.260", "references": [ { "source": "ics-cert@hq.dhs.gov", "tags": [ "Third Party Advisory", "US Government Resource" ], "url": "https://ics-cert.us-cert.gov/advisories/ICSA-18-200-03" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Third Party Advisory", "US Government Resource" ], "url": "https://ics-cert.us-cert.gov/advisories/ICSA-18-200-03" } ], "sourceIdentifier": "ics-cert@hq.dhs.gov", "vulnStatus": "Modified", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-200" } ], "source": "ics-cert@hq.dhs.gov", "type": "Secondary" }, { "description": [ { "lang": "en", "value": "CWE-200" } ], "source": "nvd@nist.gov", "type": "Primary" } ] }
Vulnerability from fkie_nvd
Published
2018-07-24 17:29
Modified
2024-11-21 04:14
Severity ?
Summary
Echelon SmartServer 1 all versions, SmartServer 2 all versions prior to release 4.11.007, i.LON 100 all versions, and i.LON 600 all versions. The devices store passwords in plaintext, which may allow an attacker with access to the configuration file to log into the SmartServer web user interface.
References
▶ | URL | Tags | |
---|---|---|---|
ics-cert@hq.dhs.gov | https://ics-cert.us-cert.gov/advisories/ICSA-18-200-03 | Third Party Advisory, US Government Resource | |
af854a3a-2127-422b-91ae-364da2661108 | https://ics-cert.us-cert.gov/advisories/ICSA-18-200-03 | Third Party Advisory, US Government Resource |
Impacted products
Vendor | Product | Version | |
---|---|---|---|
echelon | smartserver_1_firmware | - | |
echelon | smartserver_1 | - | |
echelon | smartserver_2_firmware | * | |
echelon | smartserver_2 | - | |
echelon | i.lon_100_firmware | - | |
echelon | i.lon_100 | - | |
echelon | i.lon_600_firmware | - | |
echelon | i.lon_600 | - |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:o:echelon:smartserver_1_firmware:-:*:*:*:*:*:*:*", "matchCriteriaId": "82A8FFC2-7191-42FE-8F71-77DE83945FFA", "vulnerable": true } ], "negate": false, "operator": "OR" }, { "cpeMatch": [ { "criteria": "cpe:2.3:h:echelon:smartserver_1:-:*:*:*:*:*:*:*", "matchCriteriaId": "9D78AEC2-D6E0-42EE-AEF4-5AEBA6B29611", "vulnerable": false } ], "negate": false, "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:o:echelon:smartserver_2_firmware:*:*:*:*:*:*:*:*", "matchCriteriaId": "83547993-8A11-4A60-9CBE-3CD006272A1C", "versionEndExcluding": "4.11.007", "vulnerable": true } ], "negate": false, "operator": "OR" }, { "cpeMatch": [ { "criteria": "cpe:2.3:h:echelon:smartserver_2:-:*:*:*:*:*:*:*", "matchCriteriaId": "418DEBAC-57D5-4BA8-806B-3DC235F1B625", "vulnerable": false } ], "negate": false, "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:o:echelon:i.lon_100_firmware:-:*:*:*:*:*:*:*", "matchCriteriaId": "4DC38B32-715F-4ECA-AA60-15BE5EEB0DDE", "vulnerable": true } ], "negate": false, "operator": "OR" }, { "cpeMatch": [ { "criteria": "cpe:2.3:h:echelon:i.lon_100:-:*:*:*:*:*:*:*", "matchCriteriaId": "D195E8CF-A5E2-4799-A0EF-189A825BB3AF", "vulnerable": false } ], "negate": false, "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:o:echelon:i.lon_600_firmware:-:*:*:*:*:*:*:*", "matchCriteriaId": "D1F3F845-E167-48A6-B159-39634D4D5DEB", "vulnerable": true } ], "negate": false, "operator": "OR" }, { "cpeMatch": [ { "criteria": "cpe:2.3:h:echelon:i.lon_600:-:*:*:*:*:*:*:*", "matchCriteriaId": "129D5CFF-EE75-4AED-89B1-DD947359DFFE", "vulnerable": false } ], "negate": false, "operator": "OR" } ], "operator": "AND" } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "Echelon SmartServer 1 all versions, SmartServer 2 all versions prior to release 4.11.007, i.LON 100 all versions, and i.LON 600 all versions. The devices store passwords in plaintext, which may allow an attacker with access to the configuration file to log into the SmartServer web user interface." }, { "lang": "es", "value": "Echelon SmartServer 1 en todas las versiones, SmartServer 2 en todas las versiones anteriores a 4.11.007, i.LON 100 en todas las versiones y i.LON 600 en todas las versiones. El dispositivo almacena contrase\u00f1as en texto plano, lo que podr\u00eda permitir que un atacante con acceso al archivo de configuraci\u00f3n inicie sesi\u00f3n en la interfaz web de usuario de SmartServer." } ], "id": "CVE-2018-8851", "lastModified": "2024-11-21T04:14:27.100", "metrics": { "cvssMetricV2": [ { "acInsufInfo": false, "baseSeverity": "MEDIUM", "cvssData": { "accessComplexity": "LOW", "accessVector": "NETWORK", "authentication": "NONE", "availabilityImpact": "NONE", "baseScore": 5.0, "confidentialityImpact": "PARTIAL", "integrityImpact": "NONE", "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N", "version": "2.0" }, "exploitabilityScore": 10.0, "impactScore": 2.9, "obtainAllPrivilege": false, "obtainOtherPrivilege": false, "obtainUserPrivilege": false, "source": "nvd@nist.gov", "type": "Primary", "userInteractionRequired": false } ], "cvssMetricV30": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 9.8, "baseSeverity": "CRITICAL", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "version": "3.0" }, "exploitabilityScore": 3.9, "impactScore": 5.9, "source": "nvd@nist.gov", "type": "Primary" } ] }, "published": "2018-07-24T17:29:00.353", "references": [ { "source": "ics-cert@hq.dhs.gov", "tags": [ "Third Party Advisory", "US Government Resource" ], "url": "https://ics-cert.us-cert.gov/advisories/ICSA-18-200-03" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Third Party Advisory", "US Government Resource" ], "url": "https://ics-cert.us-cert.gov/advisories/ICSA-18-200-03" } ], "sourceIdentifier": "ics-cert@hq.dhs.gov", "vulnStatus": "Modified", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-256" } ], "source": "ics-cert@hq.dhs.gov", "type": "Secondary" }, { "description": [ { "lang": "en", "value": "CWE-522" } ], "source": "nvd@nist.gov", "type": "Primary" } ] }