Executive Summary

Summary
Title GE Fanuc Proficy Information Portal allows arbitrary file upload and execution
Informations
Name VU#339345 First vendor Publication 2008-01-25
Vendor VU-CERT Last vendor Modification 2008-01-31
Severity (Vendor) N/A Revision M

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:L/Au:N/C:P/I:P/A:P)
Cvss Base Score 7.5 Attack Range Network
Cvss Impact Score 6.4 Attack Complexity Low
Cvss Expoit Score 10 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

Vulnerability Note VU#339345

GE Fanuc Proficy Information Portal allows arbitrary file upload and execution

Overview

GE Fanuc Proficy Information Portal allows authenticated users to upload arbitrary files. An attacker could upload an executable server-side script (e.g., an .asp shell on a Microsoft Internet Information Server platform) and execute arbitrary commands with the privileges of the web server.

I. Description

GE Fanuc Proficy Information Portal is a web-based systems reporting tool often used to consolidate and integrate online and process-based systems data between Supervisory Control And Data Acquisition (SCADA) systems and the corporate network. Proficy Information Portal supports an "Add WebSource" feature that allows authenticated users to upload arbitrary files to the server. An uploaded file can subsequently be executed by requesting it with a web browser.

This vulnerability affects GE Fanuc Proficy Information Portal up to and including version 2.6.

II. Impact

By uploading a file that can be executed by the web server (e.g., an .asp shell), a remote, authenticated attacker may be able to execute arbitrary code. The attacker could exploit this behavior to access SCADA networks.

III. Solution

Patch

This vulnerability will be addressed with a Software Improvement Module (SIM) for PROFICY 2.6. For more information about the availablitiy of this SIM, Proficy customers should refer to GE Fanuc knowledge base article KB12460.

Upgrade

Users of affected software with versions older than 2.6 are encouraged to upgrade to 2.6 or greater and then apply the patches discribed above. For more information, Proficy customers should refer to GE Fanuc knowledge base article KB12460.

Restrict Access

Limit network access to hosts that require connections to the portal. Do not allow access to the portal from untrusted networks such as the internet.

Filter URLs

Using a reverse HTTP proxy, web server URL filtering, or similar technology, it may be possible to restrict the names and extensions of files that can be uploaded to the Proficy Information Portal.

Modify Web Server Permissions

It may be possible to modify web server permissions to prevent file uploads. This may impact portal functionality.

Systems Affected

VendorStatusDate Updated
GE FanucVulnerable25-Jan-2008

References


http://www.securityfocus.com/archive/1/487079/30/0/threaded
http://support.gefanuc.com/support/index?page=kbchannel&id=KB12460

Credit

This vulnerability was reported by Eyal Udassin of C4 Security.

This document was written by Chris Taschner.

Other Information

Date Public01/24/2008
Date First Published01/25/2008 03:32:45 PM
Date Last Updated01/31/2008
CERT Advisory 
CVE NameCVE-2008-0175
US-CERT Technical Alerts 
Metric0.84
Document Revision35

Original Source

Url : http://www.kb.cert.org/vuls/id/339345

Open Source Vulnerability Database (OSVDB)

Id Description
41333 GE Fanuc Proficy Real-Time Information Portal Unrestricted File Upload Arbitr...

Snort® IPS/IDS

Date Description
2017-08-03 GE Fanuc Real Time Information Portal arbitrary file write attempt
RuleID : 43436 - Revision : 2 - Type : SERVER-WEBAPP