09 февраля 2018
KLCERT-18-001: Saperion webclient multiple vulnerabilities: Remote Code Execution with system user privileges in Saperion web client
Vendor
Saperion
-
CVE-IDS
-
KLCERT
KLCERT-18-001
Timeline
Timeline
-
Kaspersky ICS CERT advisory published
12 февраля 2018
-
Vendor refused to release security patch
11 января 2018
-
Vulnerabilities reported
08 августа 2017
Description
CVSS v3
Exploitability
Remotely
Attack complexity
User interaction
Impact
Existence of exploit
Unknown
Affected products
SAPERION Web Client version 7.5.2 83166
Mitigation
Vendor mitigation
N/A
Kaspersky Lab mitigation
Please use an intrusion detection system and dedicated systems designed to protect the network perimeter on industrial networks, as well as implementing tools that protect web servers and applications (web application firewall), restricting access to the vulnerable web application from the Internet and from networks adjacent to the ICS network.
Kaspersky Lab publishes information on newly identified vulnerabilities in order to raise user awareness of the IT security threats detected. Kaspersky Lab does not make any guarantees in respect of information received from vendors of products in which vulnerabilities have been identified, which is included in the following sections of the advisory: Affected Products, Vendor Mitigation.
Timeline
-
Kaspersky ICS CERT advisory published
12 февраля 2018
-
Vendor refused to release security patch
11 января 2018
-
Vulnerabilities reported
08 августа 2017