NVD disclosure day

Published threat advisories for July 24, 2018

CVE advisoryCRITICAL

CVE-2018-8859

Echelon SmartServer Authentication Bypass Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Certain Echelon devices, including SmartServer and i.LON products, have a flaw that allows unauthorized access by bypassing authentication controls. This occurs when attackers manipulate directory names. The risk involves unauthorized access to systems and potential data compromise.

CVE advisoryCRITICAL

CVE-2018-8855

Echelon SmartServer and i.LON Devices Allow Unencrypted Connections.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Certain Echelon devices allow unencrypted web connections and insecure firmware updates. This presents a risk of unauthorized access and potential manipulation of device operations, impacting organizational data confidentiality and operational integrity. Attackers could exploit these weaknesses to compromise industrial

CVE advisoryCRITICAL

CVE-2018-8851

Echelon SmartServer and i.LON Password Exposure Risk

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Certain Echelon devices store passwords in plain text, enabling an attacker with configuration file access to log into the web interface. This could lead to unauthorized system access, impacting operations and data. The realistic business risk involves potential compromise of industrial control systems and related oper