Skip to main content

CredSSP Flaw Exposes Pepperl+Fuchs HMI Devices to Attacks

  • July 11, 2018
  • 0 replies
  • 1 view

Jasper_The_Rasper
Moderator
Forum|alt.badge.img+54
By Eduard Kovacs on July 11, 2018
 
A vulnerability in the Credential Security Support Provider (CredSSP) authentication protocol has been found to impact several human-machine interface (HMI) products from Germany-based industrial automation firm Pepperl+Fuchs.
 
The flaw, tracked as CVE-2018-0886, affects all supported versions of Windows and it was fixed by Microsoft with its March 2018 Patch Tuesday updates.
 
The vulnerability was discovered by security firm Preempt, which has classified it as critical, but Microsoft, which believes exploitation is “less likely,” has assigned it only an “important” severity rating.
 
Full Article.