Executive brief
Hitek Software Automize, a task automation tool, uses weak encryption to protect stored passwords for SSH, SFTP, and other secure profiles. An attacker who gains access to the software's configuration files can easily decrypt these passwords. This could lead to the full compromise of remote servers and sensitive data transfers managed by the automation software.
Technical details
The vulnerability exists in the hitek.jar component of Hitek Software Automize due to the use of inadequate encryption strength (CWE-326) for sensitive credentials. Attackers can retrieve encrypted password strings from the sshProfiles.jsd and encryptionProfiles.jsd configuration files. Because the encryption implementation is weak, these strings can be decrypted to recover the original cleartext passwords. The attack requires access to the configuration files, but the CVSS vector suggests a network-based high-complexity path. Affected versions include the 10.x branch up to 10.25 and the 11.x branch up to 11.14.
Affected products
- Hitek Software Automize 10.x up to 10.25, 11.x up to 11.14
Timeline
- 2017-01-23: disclosed: NVD publication date