Junglewise Threat Intelligence

CVE-2016-10101: Hitek Software Automize information disclosure in passManager.jsd

CVE-2016-10101 · Severity: high · CVSS 8.1 · Published 2017-01-23

Technologies: Hitek Software Automize.

Executive brief

A vulnerability in Hitek Software's Automize automation software allows unauthorized access to stored credentials. By exploiting improper file permissions, an attacker can retrieve encrypted passwords used to manage the system. This could lead to a full takeover of the automation tasks and access to other integrated business systems.

Technical details

An information disclosure vulnerability exists in Hitek Software Automize versions 10.x and 11.x within the passManager.jsd component. The vulnerability stems from improper credential management (CWE-255) and inadequate encryption strength (CWE-326), where the passManager.jsd file is configured with Read attributes that allow unauthorized users to access it. An attacker can exploit this to retrieve encrypted passwords. While the attack requires high complexity (AC:H) according to the CVSS vector, successful exploitation allows the attacker to recover the master password or other stored credentials, potentially leading to full system compromise.

Affected products

  • Hitek Software Automize 10.x, 11.x

Timeline

  • 2017-01-23: disclosed
  • 2017-01-23: advisory

References