6.4
CVSSv2

CVE-2013-2826

Published: 15/01/2014 Updated: 16/01/2014
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
VMScore: 570
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

WellinTech KingSCADA prior to 3.1.2, KingAlarm&Event prior to 3.1, and KingGraphic prior to 3.1.2 perform authentication on the KAEClientManager console rather than on the server, which allows remote malicious users to bypass intended access restrictions and discover credentials via a crafted packet to TCP port 8130.

Vulnerable Product Search on Vulmon Subscribe to Product

wellintech kingalarm\\&event

wellintech kingscada

wellintech kinggraphic