Improper authentication in Siemens OZW772 and Siemens OZW672 - CVE-2017-6872

 

Improper authentication in Siemens OZW772 and Siemens OZW672 - CVE-2017-6872

Published: July 7, 2017


Vulnerability identifier: #VU7372
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-6872
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to obtain data on the target system.

The weakness exists due to improper authentication. A remote attacker with access to Port 21/TCP can access or alter historical measurement data stored on the device.

Successful exploitation of the vulnerability results in information disclosure and modification.

Affected software

Siemens OZW772
Siemens OZW672

How to mitigate CVE-2017-6872

Cybersecurity Help is currently unaware of any official patch addressing the vulnerability.



External References

Related Security Bulletins