Vulnerability Description
Intellicom NetBiter WebSCADA devices use default passwords for the HICP network configuration service, which makes it easier for remote attackers to modify network settings and cause a denial of service. NOTE: this is only a vulnerability when the administrator does not follow recommendations in the product's installation documentation. NOTE: this issue was originally reported to be hard-coded passwords, not default passwords.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Intellicom | Netbiter Webscada Firmware | 3.11.0 |
| Intellicom | Netbiter Webscada Ws100 | All versions |
| Intellicom | Netbiter Webscada Ws200 | All versions |
Related Weaknesses (CWE)
References
- http://blog.48bits.com/?p=781
- http://reversemode.com/index.php?option=com_content&task=view&id=65&Itemid=1Exploit
- http://support.intellicom.se/getfile.cfm?FID=151
- http://www.kb.cert.org/vuls/id/902793US Government Resource
- http://www.osvdb.org/61506
- http://www.securityfocus.com/archive/1/508449/100/0/threaded
- http://blog.48bits.com/?p=781
- http://reversemode.com/index.php?option=com_content&task=view&id=65&Itemid=1Exploit
- http://support.intellicom.se/getfile.cfm?FID=151
- http://www.kb.cert.org/vuls/id/902793US Government Resource
- http://www.osvdb.org/61506
- http://www.securityfocus.com/archive/1/508449/100/0/threaded
FAQ
What is CVE-2009-4463?
CVE-2009-4463 is a vulnerability with a CVSS score of 10.0 (HIGH). Intellicom NetBiter WebSCADA devices use default passwords for the HICP network configuration service, which makes it easier for remote attackers to modify network settings and cause a denial of servi...
How severe is CVE-2009-4463?
CVE-2009-4463 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2009-4463?
Check the references section above for vendor advisories and patch information. Affected products include: Intellicom Netbiter Webscada Firmware, Intellicom Netbiter Webscada Ws100, Intellicom Netbiter Webscada Ws200.