TURCK BL20 / BL67 FTP Service Hardcoded Credentials Security

by Carol~ Moderator - 5/17/13 9:26 AM

In Reply to: VULNERABILITIES / FIXES - May 17, 2013 by Carol~ Moderator

TURCK BL20 / BL67 FTP Service Hardcoded Credentials Security Issues

Release Date : 2013-05-17

Criticality level : Less critical
Impact : Security Bypass
Where : From local network
Solution Status: Vendor Patch

Operating System :
TURCK BL20
TURCK BL67

Description:
Some security issues have been reported in TURCK BL20 / BL67, which can be exploited by malicious people to bypass certain security restrictions.

The security issues are caused due to the device using certain user accounts with hardcoded credentials for the FTP service, which can potentially be exploited to gain administrative access to the device via TCP Port 21 and subsequently manipulate device communication.

The security issues are reported in all versions.

Solution:
Apply a firmware update. Please contact the vendor for details.

Provided and/or discovered by:
ICS-CERT credits Ruben Santamarta, IOActive.

Original Advisory:
http://ics-cert.us-cert.gov/advisories/ICSA-13-136-01

http://secunia.com/advisories/53456/