10

CVE-2009-0216

GE Fanuc iFIX 5.0 and earlier relies on client-side authentication involving a weakly encrypted local password file, which allows remote attackers to bypass intended access restrictions and start privileged server login sessions by recovering a password or by using a modified program module.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ge Fanuc ≫ Ifix Version <= 5.0
Ge Fanuc ≫ Ifix Version 2.0
Ge Fanuc ≫ Ifix Version 2.2
Ge Fanuc ≫ Ifix Version 2.5
Ge Fanuc ≫ Ifix Version 2.6
Ge Fanuc ≫ Ifix Version 2.21
Ge Fanuc ≫ Ifix Version 3.0
Ge Fanuc ≫ Ifix Version 3.5
Ge Fanuc ≫ Ifix Version 4.0
Ge Fanuc ≫ Ifix Version 4.5
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.98% 0.855
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://support.gefanuc.com/support/index?page=kbchannel&id=S:KB13253&actp=search
Vendor Advisory
http://www.kb.cert.org/vuls/id/310355
US Government Resource
http://www.mcgrewsecurity.com/2009/02/10/ge-fanuc-releases-info-on-ifix-vulnerabilities-vu-310355/
http://www.securityfocus.com/bid/33739
https://exchange.xforce.ibmcloud.com/vulnerabilities/48691