vendor:
WebVisit
by:
Deneut Tijl
7.3
CVSS
HIGH
Password Disclosure
200
CWE
Product Name: WebVisit
Affected Version From: WebVisit < 6.40.00
Affected Version To: WebVisit < 6.40.00
Patch Exists: YES
Related CWE: CVE-2016-8366
CPE: a:phoenix_contact:webvisit
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: ILC-390 PLC
2018
Phoenix Contact WebVisit 6.40.00 – Password Disclosure
This script will perform retrieval of clear text credentials for a Phoenix Contact PLC with a WebVisit GUI, password protected, application on it. Tested on the Phoenix Contact ILC-390 PLC, but others are surely equally vulnerable with WebVisit 6.40.00, the passwords are SHA256 hashes, which also will be retrieved.
Mitigation:
Upgrade to WebVisit 6.40.00 or later versions