Junglewise Threat Intelligence

CVE-2016-10103: Hitek Software Automize information disclosure in encryptionProfiles.jsd

CVE-2016-10103 · Severity: high · CVSS 8.1 · Published 2017-01-23

Technologies: Hitek Software Automize.

Executive brief

Hitek Software Automize, an automation and task scheduling tool, contains a security flaw that allows unauthorized users to access sensitive configuration files. This vulnerability enables an attacker to retrieve encrypted passwords used for GPG encryption profiles. If exploited, this could lead to the compromise of secure communications and sensitive data handled by the automation software.

Technical details

An information disclosure vulnerability exists in Hitek Software Automize due to insecure file permissions on the 'encryptionProfiles.jsd' configuration file. The file is configured with 'Read' attributes for the 'Users' group, allowing unauthorized access to its contents. An attacker can exploit this to recover encrypted passwords associated with GPG Encryption profiles. The vulnerability affects all 10.x versions up to 10.25 and all 11.x versions up to 11.14. While the CVSS vector indicates a network attack vector, the root cause is a local permission misconfiguration that may be accessible via network-based file sharing or application interfaces.

Affected products

  • Hitek Software Automize 10.x up to 10.25, 11.x up to 11.14

Timeline

  • 2017-01-23: disclosed
  • 2017-01-23: advisory

References