Security News > 2023 > August > Multiple Flaws Found in ScrutisWeb Software Exposes ATMs to Remote Hacking

Multiple Flaws Found in ScrutisWeb Software Exposes ATMs to Remote Hacking
2023-08-15 16:44

Four security vulnerabilities in the ScrutisWeb ATM fleet monitoring software made by Iagona could be exploited to remotely break into ATMs, upload arbitrary files, and even reboot the terminals.

The issues have been addressed in ScrutisWeb version 2.1.38.

ScrutisWeb is a web browser-based solution for monitoring banking and retail ATM fleets, including gleaning information system status, detecting low paper alerts, shutting down or restarting a terminal, and remotely modifying data.

The most severe of the flaws is CVE-2023-35189, as it enables an unauthenticated user to upload any file and then view it again from a web browser, resulting in command injection.

"From here, a malicious actor would be able to monitor activities on individual ATMs within the fleet. The console also allows for dropping ATMs into management mode, uploading files to them, rebooting them, and powering them completely off," Synack said.

CVE-2023-35189 could be used to delete log files on ScrutisWeb to cover up the tracks.


News URL

https://thehackernews.com/2023/08/multiple-flaws-found-in-scrutisweb.html

Related Vulnerability

DATE CVE VULNERABILITY TITLE RISK
2023-07-18 CVE-2023-35189 Unrestricted Upload of File with Dangerous Type vulnerability in Iagona Scrutisweb
Iagona ScrutisWeb versions 2.1.37 and prior are vulnerable to a remote code execution vulnerability that could allow an unauthenticated user to upload a malicious payload and execute it.
network
low complexity
iagona CWE-434
critical
9.8