Siemens Synco OZW Web Server < 4.0 Default Password

high Nessus Network Monitor Plugin ID 720021

Synopsis

The Siemens Synco OZW Web Server contains a default password.

Description

The Siemens Synco OZW Web Server devices OZW672.*, OZW772.*, and OZW775 with firmware before 4 have an unspecified default password, which makes it easier for remote attackers to obtain administrative access via a network session.

Solution

Perform vendor recommended mitigations and apply available vendor upgrades.

See Also

http://support.automation.siemens.com/WW/view/en/41929231/130000,https://ics-cert.us-cert.gov/advisories/ICSA-12-214-01,http://www.us-cert.gov/control_systems/pdf/ICSA-12-214-01.pdf

Plugin Details

Severity: High

ID: 720021

Family: SCADA

Published: 5/8/2019

Updated: 9/30/2019

Risk Information

VPR

Risk Factor: Medium

Score: 5.8

CVSS v2

Risk Factor: High

Base Score: 7.5

Temporal Score: 5.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Information

Patch Publication Date: 8/1/2012

Vulnerability Publication Date: 8/1/2012

Reference Information

CVE: CVE-2012-3020