First published: Tue Dec 18 2012(Updated: )
Invensys Wonderware InTouch 2012 R2 and earlier and Siemens ProcessSuite use a weak encryption algorithm for data in Ps_security.ini, which makes it easier for local users to discover passwords by reading this file.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Wonderware InTouch | <=2012 | |
Siemens ProcessSuite |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-4693 has been assigned a medium severity rating due to its weak encryption vulnerability.
To mitigate CVE-2012-4693, update to a newer version of Invensys Wonderware InTouch or Siemens ProcessSuite that addresses this security issue.
CVE-2012-4693 affects Invensys Wonderware InTouch up to version 2012 R2 and Siemens ProcessSuite.
CVE-2012-4693 is a vulnerability related to weak encryption used for storing sensitive data.
Yes, local users may exploit CVE-2012-4693 to discover passwords by accessing the Ps_security.ini file.