Brief

Summary:

Vulnerability Alert: EFACEC UC 500E HMI

A total of four vulnerabilities have been identified in the EFACEC UC 500E Human-Machine Interface (HMI), which could allow an attacker to retrieve sensitive information, gain unauthorized access, or redirect users to malicious websites. The vulnerabilities include:

1. Cleartext Transmission of Sensitive Information (CVSS v3 score: 6.3)
2. Open Redirect (CVSS v3 score: 4.3)
3. Exposure of Sensitive Information to an Unauthorized Actor (CVSS v3 score: 5.3)
4. Improper Access Control (CVSS v3 score: 4.1)

These vulnerabilities affect the UC 500E version 10.1.0 and have been assigned CVE-2023-50703, CVE-2023-50704, CVE-2023-50705, and CVE-2023-50706. Aaru00f3n Flecha Menu00e9ndez of S21sec reported these vulnerabilities to CISA.

CISA recommends the following mitigations:

Minimize network exposure and use firewalls to isolate control systems
Use secure remote access methods, such as Virtual Private Networks (VPNs)
Perform impact analysis and risk assessment prior to deploying defensive measures
Implement recommended cybersecurity strategies for proactive defense of ICS assets

No known public exploitation of these vulnerabilities has been reported at this time. EFACEC has released UC 500E version 10.1.1 to mitigate these vulnerabilities.

View CSAF 1. EXECUTIVE SUMMARY CVSS v3 6.3 ATTENTION: Exploitable remotely/low attack complexity Vendor: EFACEC Equipment: UC 500 Vulnerabilities: Cleartext Transmission of Sensitive Information, Open Redirect, Exposure of Sensitive Information to an Unauthorized Actor, Improper Access Control 2. RISK EVALUATION Successful exploitation of these vulnerabilities could allow an attacker to retrieve sensitive information, gain unauthorized

This content is restricted.

Highlights content goes here...

View CSAF 1. EXECUTIVE SUMMARY CVSS v3 6.3 ATTENTION: Exploitable remotely/low attack complexity Vendor: EFACEC Equipment: UC 500 Vulnerabilities: Cleartext Transmission of Sensitive Information, Open Redirect, Exposure of Sensitive Information to an Unauthorized Actor, Improper Access Control 2. RISK EVALUATION Successful exploitation of these vulnerabilities could allow an attacker to retrieve sensitive information, gain unauthorized

This content is restricted.

Cybersecurity and Infrastructure Security Agency

Quick Insight
RADA.AI
RADA.AI
Hello! I'm RADA.AI - Regulatory Analysis and Decision Assistance. Your Intelligent guide for compliance and decision-making. How can i assist you today?
Suggested

Form successfully submitted. One of our GRI rep will contact you shortly

Thanking You!

Enter your Email

Enter your registered username/email id.

Enter your Email

Enter your email id below to signup.
Individual Plan
$125 / month OR $1250 / year
Features
Best for: Researchers, Legal professionals, Academics
Enterprise Plan
Contact for Pricing
Features
Best for: Law Firms, Corporations, Government Bodies