ICSA-17-096-01A
·
Published 2017-04-27
·
View on CISA ICS-CERT ↗
Certec EDV GmbH atvise scada (Update A)
CVSS 6.1
MEDIUM
Risk Summary
ATTENTION: Remotely exploitable/low skill level to exploit.
CVEs (2)
Remediations
- Certec EDV GmbH advises affected users to activate the built-in security mechanism (login, https, protected calls, etc.) of the product as described in the documentation. Users can also upgrade to the newest version of the software available on the Certec EDV GmbH web site (a user login will be needed to obtain the latest version):
- In order to fully mitigate the vulnerabilities Certec EDV GmbH recommends that users follow the guidelines in the atvise scada documentation for enabling security measures that can be found in the following sections:HTTP/HTTPS support,Protected calls,Login and user management, and User and rights.
Affected Vendors
Certec EDV GmbH
Affected Products (1)
Certec EDV GmbH
·
atvise scada
< 3.0
Get alerted to advisories like this
OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.
Start free trial Learn more