[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [FD] Security advisory: multiple vulnerabilities including Default-credential RCE, Pre-authentication root RCE in atvise SCADA 3.13.0 (atvise GmbH / Bachmann Visutec)



Reference: https://seclists.org/fulldisclosure/2026/Aug/5

I tested both vulnerabilities against a clean installation of atvise SCADA 
3.13.0. Results differ between the two findings.

---

Vulnerability 1 (OPC UA pre-authentication root RCE, CVSS 9.8) - NOT 
REPRODUCIBLE

The ActivateSession step - identified as the authentication bypass entry point 
- returns BadUserAccessDenied:

    WebMI login(root, bogus) -> 200 {"error":-1,"errorstring":"Invalid Session 
or Digest"}
        [+] root has a strong password (bogus login rejected)
    [Step 1] OPC UA 4840 ActivateSession(root, bogus) -- authentication bypass
    ServiceFault (BadUserAccessDenied, diagnostics: DiagnosticInfo(
      SymbolicId=None, NamespaceURI=None, Locale=None,
      LocalizedText=None, AdditionalInfo=None,
      InnerStatusCode=None, InnerDiagnosticInfo=None))
    from server received in response to ActivateSessionRequest

The OPC UA backend rejects the bogus password and does not yield a superuser 
session, contrary to the advisory's claim that logonSessionUser never calls the 
password-verification function.

Note for anyone attempting independent reproduction: the advisory's license 
note discloses that the research was conducted against a binary-patched 
installation (patch 5: isLicensed() forced to 1; patch 6: session-count 
bypass). Whether OPC UA authentication behaviour differs between the patched 
binary and an unmodified licensed installation remains the open question. If 
the 0day Rubbish Research Team can clarify whether the ActivateSession step was 
verified against the original unpatched binary, that would help resolve the 
discrepancy.

---

Vulnerability 2 (WebMI default-credential RCE, CVSS 8.8) - REPRODUCIBLE

Confirmed. login(root, <any value>) returns {"username":"root"} on a 
factory-default installation. The handleLogin 'password not set' branch behaves 
exactly as described. Setting a strong root password via changepassword closes 
the bypass.

Mit freundlichen Grüßen
With kind regards

Ing. Daniel Lomosits MSc MBA BSc
Product Manager

P +43 (0)2682 / 75799-2829 M +43 (0) 676 / 702 80 87 | 
daniel.lomosits@xxxxxxxxxxxxx<mailto:daniel.lomosits@xxxxxxxxxxxxx> | 
www.bachmann-visutec.com<http://www.bachmann-visutec.com/>

[cid:image001.png@01DD2E3D.5EAA1330]<https://atvise.com/>

Registered Office:
Bachmann Visutec GmbH, Kasernenstraße 29, 7000 Eisenstadt, Austria
FN 274018v Commercial Register Eisenstadt | ATU 62240738
Corporate Headquarters:
Bachmann electronic GmbH, Kreuzäckerweg 33, 6800 Feldkirch, Austria
FN 75348g Commercial Register Feldkirch | ATU 36410905

Dokumente mit rechtsverbindlichem Inhalt sind nur mit Originalunterschrift 
wirksam.
Documents with legally binding subject matter are valid only with original 
hand-written signature.

Follow Bachmann on  Facebook<https://www.facebook.com/Bachmann.electronic/> |  
LinkedIn<https://www.linkedin.com/company/bachmann-electronic-gmbh> |  
Twitter<https://twitter.com/bachmann_corp> |  
Xing<https://www.xing.com/companies/bachmannelectronicgmbh> |  
YouTube<https://www.youtube.com/channel/UCE5LllKmEA5ZtBnsIpvVqxg>

PNG image

_______________________________________________
Sent through the Full Disclosure mailing list
https://nmap.org/mailman/listinfo/fulldisclosure
Web Archives & RSS: https://seclists.org/fulldisclosure/