Junglewise Threat Intelligence

CVE-2016-10104: Hitek Software Automize information disclosure in sshProfiles.jsd

CVE-2016-10104 · Severity: medium · CVSS 5.9 · Published 2017-01-23

Technologies: Hitek Software Automize.

Executive brief

Hitek Software Automize, an automation and task scheduling tool, contains a security flaw that allows unauthorized access to sensitive connection details. An attacker can retrieve encrypted passwords for SSH and SFTP profiles, potentially leading to unauthorized access to remote servers and data. This occurs because certain configuration files are incorrectly set to be readable by all users.

Technical details

An information disclosure vulnerability exists in Hitek Software Automize versions 10.x through 10.25 and 11.x through 11.14. The vulnerability stems from insecure file permissions on the 'sshProfiles.jsd' file, which has the 'Read' attribute enabled for the 'Users' group. This allows an attacker with network access to the system to read the file and recover encrypted passwords for SSH and SFTP profiles. While the passwords are encrypted, the inadequate encryption strength (CWE-326) may allow for their recovery, leading to further compromise of remote systems.

Affected products

  • Hitek Software Automize 10.x up to 10.25, 11.x up to 11.14

Timeline

  • 2017-01-23: advisory: NVD publication date

References