10
CVSSv2

CVE-2009-0216

Published: 13/02/2009 Updated: 08/08/2017
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

GE Fanuc iFIX 5.0 and previous versions relies on client-side authentication involving a weakly encrypted local password file, which allows remote malicious users to bypass intended access restrictions and start privileged server login sessions by recovering a password or by using a modified program module.

Vulnerable Product Search on Vulmon Subscribe to Product

ge fanuc ifix

ge fanuc ifix 2.21

ge fanuc ifix 2.2

ge fanuc ifix 3.5

ge fanuc ifix 3.0

ge fanuc ifix 2.6

ge fanuc ifix 2.5

ge fanuc ifix 4.5

ge fanuc ifix 4.0

ge fanuc ifix 2.0

Github Repositories

dumps credentials from GE Fanuc Proficy HMI/SCADA iFix XTCOMPAT.UTL files

ifixpwdump dumps credentials from iFix XTCOMPATUTL files Vulnerability GE Fanuc Proficy HMI/SCADA iFIX uses insecure authentication techniques wwwkbcertorg/vuls/id/310355 wwwsecurityfocuscom/bid/33739 cvemitreorg/cgi-bin/cvenamecgi?name=CVE-2009-0216 php vs py php: old, crapy code (2011) py: new, a little less crapy code (2017)