Stories
Slash Boxes
Comments

SoylentNews is people

SoylentNews is powered by your submissions, so send in your scoop. Only 19 submissions in the queue.

Submission Preview

Link to Story

Advantech authentication forgets the authentication part

Accepted submission by VanderDecken at 2016-01-19 05:10:40
Security

The Register reports that Advantech EKI series of Modbus-to-TCP gateways have been shipping with a modified SSH daemon that will accept any username and password for authentication [theregister.co.uk]. The devices, which are commonly used in SCADA applications for connecting remote devices to supervisory computers, were previously reported for other vulnerabilities Shellshock and Heartbleed.

In addition to the above problem, a hardcoded debugging username/password was also apparently left in the firmware and active.


Original Submission