Improper input validation in Panel Builder 800 - CVE-2018-10616
Published: July 17, 2018 / Updated: July 18, 2018
Vulnerability details
The vulnerability allows a local attacker to execute arbitrary code on the target system.
The vulnerability exists due to an error when processing malicious input. A local attacker can trick the victim into opening a specially crafted file, insert and run arbitrary code with elevated privileges.
Successful exploitation of the vulnerability may result in system compromise.
Affected software
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power
Opensuse
How to mitigate CVE-2018-10616
- Conduct or reinforce cybersecurity awareness training for users of Panel Builder 800:
- Describing general cybersecurity best practice recommendations for industrial control systems,
- Informing that it is possible to infect Panel Builder files with malware,
- Describing the importance of being careful with files that are received unexpectedly and/or from unexpected sources.
- Carefully inspecting any files transferred between computers, including scanning them with up-to-date antivirus software, so that only the legitimate files are being transferred.
- User account management, appropriate authentication and permission management using the principle of least privilege.