CVE-2012-4693: Weak Encryption
Published Dec 18, 2012
·Updated
Invensys Wonderware InTouch 2012 R2 and earlier and Siemens ProcessSuite use a weak encryption algorithm for data in Pssecurity.ini, which makes it easier for local users to discover passwords by reading this file.
Affected Software
2 affected components
Invensys Wonderware InTouch<=2012
Siemens ProcessSuite
Event History
Dec 18, 2012
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-4693?
CVE-2012-4693 has been assigned a medium severity rating due to its weak encryption vulnerability.
2
How do I fix CVE-2012-4693?
To mitigate CVE-2012-4693, update to a newer version of Invensys Wonderware InTouch or Siemens ProcessSuite that addresses this security issue.
3
What systems are affected by CVE-2012-4693?
CVE-2012-4693 affects Invensys Wonderware InTouch up to version 2012 R2 and Siemens ProcessSuite.
4
What type of vulnerability is CVE-2012-4693?
CVE-2012-4693 is a vulnerability related to weak encryption used for storing sensitive data.
5
Can local users exploit CVE-2012-4693?
Yes, local users may exploit CVE-2012-4693 to discover passwords by accessing the Ps_security.ini file.