Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2012-5862

Overview

Vulnerability Score 10.0 10.0
CVE Id CVE-2012-5862
Last Modified 02 Feb 2013 12:10:18
Published 23 Nov 2012 07:09:58
Confidentiality Impact COMPLETE COMPLETE
Integrity Impact COMPLETE COMPLETE
Availability Impact COMPLETE COMPLETE
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2012-5862

Summary

login.php on the Sinapsi eSolar Light Photovoltaic System Monitor (aka Schneider Electric Ezylog photovoltaic SCADA management server), Sinapsi eSolar, and Sinapsi eSolar DUO with firmware before 2.0.2870_2.2.12 establishes multiple hardcoded accounts, which makes it easier for remote attackers to obtain administrative access by leveraging a (1) cleartext password or (2) password hash contained in this script, as demonstrated by a password of astridservice or 36e44c9b64.

Vulnerable Systems

Operating System

  • Sinapsitech Sinapsi Firmware 2.0.2870


References

MISC - http://www.us-cert.gov/control_systems/pdf/ICSA-12-325-01.pdf

EXPLOIT-DB - 21273

BUGTRAQ - 20120911 Multiple vulnerabilities in Ezylog photovoltaic management server

XF - sinapsi-default-password(80200)

CONFIRM - http://www.sinapsitech.it/default.asp?active_page_id=78&news_id=88


Last Updated: 27 May 2016 11:01:46