An insecure communication was found between a user and the Orpak SiteOmat management console for all known versions, due to an invalid SSL certificate. The attack allows for an eavesdropper to capture the communication and decrypt the data.
Weaknesses in this category are related to the design and implementation of data confidentiality and integrity. Frequently these deal with the use of encoding techniques, encryption libraries, and hashing algorithms. The weaknesses in this category could lead to a degradation of the quality data if they are not addressed.
Link | Tags |
---|---|
http://www.orpak.com | vendor advisory |
https://ics-cert.us-cert.gov/advisories/ICSA-19-122-01 | third party advisory us government resource |
http://www.securityfocus.com/bid/108167 | vdb entry third party advisory |