CVE-2016-9353
Advantech SUSIAccess Server Static Encryption Key Privilege Escalation Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
An issue was discovered in Advantech SUISAccess Server Version 3.0 and prior. The admin password is stored in the system and is encrypted with a static key hard-coded in the program. Attackers could reverse the admin account password for use.
Ha sido descubierto un problema en Advantech SUISAccess Server versión 3.0 y anteriores. La contraseña de administrador se almacena en el sistema y se cifra con una clave estática codificada en el programa. Atacantes pueden invertir la contraseña de la cuenta del administrador para usarla.
This vulnerability allows attackers to escalate privileges on vulnerable installations of Advantech SUSIAccess Server. Authentication is not required to exploit this vulnerability.
The specific flaw exists within encryption and storage of the administrator password. The password is stored in a known location and is encrypted with a static encryption key. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of SYSTEM.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2016-11-16 CVE Reserved
- 2016-12-13 CVE Published
- 2024-06-22 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-264: Permissions, Privileges, and Access Controls
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/94631 | Third Party Advisory | |
https://ics-cert.us-cert.gov/advisories/ICSA-16-336-04 | Mitigation |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Advantech Search vendor "Advantech" | Susiaccess Search vendor "Advantech" for product "Susiaccess" | <= 3.0 Search vendor "Advantech" for product "Susiaccess" and version " <= 3.0" | - |
Affected
|