Pro-face GP-Pro ex hmi Vulnerability (CVE-2015-7921)
Pro-face GP-Pro ex hmi Vulnerability (CVE-2015-7921)
Release date:
Updated on:
Affected Systems:
Proface GP-Pro EX 1.00-4.0.4
Proface GP-Pro EX
Description:
CVE (CAN) ID: CVE-2015-7921
Pro-face GP-Pro EX is an HMI Screen Editor and logic programming software.
Pro-face GP-Pro EX EX-ED earlier than 4.05.000, PFXEXEDV earlier than 4.05.000, PFXEXEDLS earlier than 4.05.000, PFXEXGRPLS earlier than 4.05.000, FTP server uses hard-coded creden, remote attackers can exploit this vulnerability to bypass authentication.
<* Source: Jeremy Brown
Link: https://ics-cert.us-cert.gov/advisories/ICSA-16-096-01
*>
Suggestion:
Vendor patch:
Proface
-------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.hmisource.com/otasuke/download/update/proex/
This article permanently updates the link address: