Honeywell FALCON XL Web Controller Multiple Vulnerabilities

high Nessus Plugin ID 77375

Synopsis

The remote host is affected by multiple vulnerabilities.

Description

The remote host is a Honeywell FALCON XL Web SCADA controller that is running a firmware version affected by the following vulnerabilities :

- The change password page can be accessed without authentication to determine users' password hashes, which can allow a remote attacker to gain administrative access. (CVE-2014-2717)

- The web server on the device is affected by multiple cross-site scripting vulnerabilities. (CVE-2014-3110)

Solution

Contact the vendor for the latest available updates.

See Also

https://ics-cert.us-cert.gov/advisories/ICSA-14-175-01

Plugin Details

Severity: High

ID: 77375

File Name: scada_xlweb_2_2_11.nbin

Version: 1.68

Type: remote

Family: SCADA

Published: 8/25/2014

Updated: 5/20/2024

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.9

CVSS v2

Risk Factor: High

Base Score: 7.6

Temporal Score: 6

Vector: CVSS2#AV:N/AC:H/Au:N/C:C/I:C/A:C

Vulnerability Information

CPE: cpe:/h:honeywell:falcon_xlweb_xlwebexe

Required KB Items: Host/XLWeb/xlweb-version

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 7/23/2014

Vulnerability Publication Date: 7/23/2014

Reference Information

CVE: CVE-2014-2717, CVE-2014-3110

BID: 68837, 68838