Skip to main navigation Skip to main content Skip to page footer

Hardcoded credentials

Security Advisories IBA-2022-04

Fondo verde con diseño de interfaz digital circular.
Publishing Date 2022-04-12
Last Update 2022-04-12
Tracking IDIBA-2022-04
CVSS Base Score2.8
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N

Summary

An attacker was able to extract hardcoded FTP credentials from the application.

Affected products

ibaPDA
All versions prior to v7.3.13

How do I know that I'm affected

Check the version number in the title of the status application on the system where the server is running.

Solution

Update to ibaPDA v7.3.13 or higher.

Customer Actions

Please update to ibaPDA v7.3.13 or higher.

Technical Details

Issue

FTP client component
The FTP client component had hardcoded default credentials for accessing FTP servers that allowed anonymous login.

Acknowledgements

Shell Marine Risk Team
Shell CyberDefence & Risk Operations Penetration Testing team

Christian EP. Wiedemer from Aspin Kemp & Associates Inc.

iba AG recognizes the efforts of those in the security community who help us to improve the security posture of the products and protect customers.

Timeline

2022-03-21Notified by Aspin Kemp & Associates Inc.
2022-04-12New ibaPDA version released
2022-04-12Security advisory published
Volver a la vista de lista

¿Qué te gustaría hacer hoy?

Al elegir un país, mi solicitud se remitirá a la sucursal de iba AG responsable de las ventas y la asistencia.Política de privacidad