ID

VAR-E-201201-0658


CVE

cve_id:CVE-2012-1807

Trust: 0.3

cve_id:CVE-2012-1808

Trust: 0.3

cve_id:CVE-2012-1805

Trust: 0.3

cve_id:CVE-2012-1806

Trust: 0.3

cve_id:CVE-2012-1809

Trust: 0.3

sources: BID: 51634

TITLE

Koyo ECOM100 Ethernet Module Multiple Security Vulnerabilities

Trust: 0.3

sources: BID: 51634

DESCRIPTION

Koyo ECOM100 Ethernet Module is prone to multiple unspecified vulnerabilities including:
1. A buffer-overflow vulnerability.
2. A denial-of-service vulnerability.
3. Multiple security-bypass vulnerabilities.
4. A cross site-scripting vulnerability.
Attackers can exploit these issues to execute arbitrary code in the context of the affected application, cause denial-of-service conditions, bypass some security restrictions, allow an attacker to steal cookie-based information, or execute script code in the context of the browser of an unsuspecting user; other attacks may also be possible.

Trust: 0.3

sources: BID: 51634

AFFECTED PRODUCTS

vendor:koyomodel:h4-ecom100scope:eqversion:0

Trust: 0.3

vendor:koyomodel:h4-ecom-fscope:eqversion:0

Trust: 0.3

vendor:koyomodel:h4-ecomscope:eqversion:0

Trust: 0.3

vendor:koyomodel:h2-ecom100scope:eqversion:0

Trust: 0.3

vendor:koyomodel:h2-ecom-fscope:eqversion:0

Trust: 0.3

vendor:koyomodel:h2-ecomscope:eqversion:0

Trust: 0.3

vendor:koyomodel:h0-ecom100scope:eqversion:0

Trust: 0.3

vendor:koyomodel:h0-ecomscope:eqversion:0

Trust: 0.3

vendor:koyomodel:ecom100 ethernet modulescope:eqversion:0

Trust: 0.3

sources: BID: 51634

EXPLOIT

A brute force password cracking tool has been released that targets the weak authentication vulnerability in the ECOM series modules. Please the references for details.

Trust: 0.3

sources: BID: 51634

PRICE

Free

Trust: 0.3

sources: BID: 51634

TYPE

Unknown

Trust: 0.3

sources: BID: 51634

CREDITS

Reid Wightman

Trust: 0.3

sources: BID: 51634

EXTERNAL IDS

db:ICS CERT ALERTid:ICS-ALERT-12-020-05

Trust: 0.3

db:ICS CERT ALERTid:ICS-ALERT-12-020-05A

Trust: 0.3

db:ICS CERTid:ICSA-12-102-02

Trust: 0.3

db:NVDid:CVE-2012-1807

Trust: 0.3

db:NVDid:CVE-2012-1808

Trust: 0.3

db:NVDid:CVE-2012-1805

Trust: 0.3

db:NVDid:CVE-2012-1806

Trust: 0.3

db:NVDid:CVE-2012-1809

Trust: 0.3

db:BIDid:51634

Trust: 0.3

sources: BID: 51634

REFERENCES

url:http://www.us-cert.gov/control_systems/pdf/icsa-12-102-02.pdf

Trust: 0.3

url:http://www.koyoele.co.jp/english/index.html

Trust: 0.3

url:http://www.us-cert.gov/control_systems/pdf/ics-alert-12-020-05a.pdf

Trust: 0.3

url:http://www.us-cert.gov/control_systems/pdf/ics-alert-12-020-05.pdf

Trust: 0.3

sources: BID: 51634

SOURCES

db:BIDid:51634

LAST UPDATE DATE

2022-07-27T09:30:26.312000+00:00


SOURCES UPDATE DATE

db:BIDid:51634date:2012-04-11T22:40:00

SOURCES RELEASE DATE

db:BIDid:51634date:2012-01-23T00:00:00