Vulnerabilities > CVE-2016-8366 - Credentials Management vulnerability in Phoenixcontact ILC Plcs Firmware

047910
CVSS 7.3 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
LOW
Integrity impact
LOW
Availability impact
LOW
network
low complexity
phoenixcontact
CWE-255
exploit available

Summary

Webvisit in Phoenix Contact ILC PLCs offers a password macro to protect HMI pages on the PLC against casual or coincidental opening of HMI pages by the user. The password macro can be configured in a way that the password is stored and transferred in clear text.

Vulnerable Configurations

Part Description Count
OS
Phoenixcontact
1
Hardware
Phoenixcontact
1

Common Weakness Enumeration (CWE)

Exploit-Db

descriptionPhoenix Contact WebVisit 6.40.00 - Password Disclosure. CVE-2016-8366. Webapps exploit for Hardware platform
fileexploits/hardware/webapps/45586.py
idEDB-ID:45586
last seen2018-10-11
modified2018-10-11
platformhardware
port
published2018-10-11
reporterExploit-DB
sourcehttps://www.exploit-db.com/download/45586/
titlePhoenix Contact WebVisit 6.40.00 - Password Disclosure
typewebapps

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/149763/phoenixcontactwebvisit64000-disclose.txt
idPACKETSTORM:149763
last seen2018-10-12
published2018-10-11
reporterDeneut Tijl
sourcehttps://packetstormsecurity.com/files/149763/Phoenix-Contact-WebVisit-6.40.00-Password-Disclosure.html
titlePhoenix Contact WebVisit 6.40.00 Password Disclosure