CVE-2016-9353: High severity Advantech Susiaccess vulnerability
An issue was discovered in Advantech SUISAccess Server Version 3.0 and prior. The admin password is stored in the system and is encrypted with a static key hard-coded in the program. Attackers could reverse the admin account password for use.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-9353?
CVE-2016-9353 is considered a high severity vulnerability due to the potential for unauthorized access to the admin account.
How do I fix CVE-2016-9353?
To mitigate CVE-2016-9353, upgrade to Advantech SUISAccess Server version 3.1 or later where the issue is resolved.
What type of vulnerability is CVE-2016-9353?
CVE-2016-9353 is classified as a credential exposure vulnerability due to the hard-coded static key used for password encryption.
Who is affected by CVE-2016-9353?
Users of Advantech SUISAccess Server versions 3.0 and earlier are affected by CVE-2016-9353.
What happens if I am impacted by CVE-2016-9353?
If impacted by CVE-2016-9353, an attacker could potentially reverse-engineer the admin password, leading to unauthorized access.