Executive brief
STER is a specialized software suite used for occupational health and safety (OHS) management and risk assessment. A security flaw in how the software handles user passwords allows an attacker to reverse-engineer and guess actual passwords by observing how known values are encoded. This could lead to unauthorized access to sensitive workplace safety data, employee records, and administrative controls within the system.
Technical details
STER software prior to version 9.5 utilizes a weak password encoding algorithm (CWE-261) rather than a secure cryptographic hash. This vulnerability allows an attacker with low-privileged local access to the system or its database to perform a known-plaintext analysis. By comparing how known input strings are transformed by the encoding routine, the attacker can derive the logic necessary to decode or guess other users' passwords. The issue is addressed in version 9.5 by implementing stronger password protection mechanisms.
Affected products
- Centralny Instytut Ochrony Pracy - Państwowy Instytut Badawczy (CIOP-PIB) STER All versions prior to 9.5
Timeline
- 2026-05-22: disclosed: Vulnerability disclosed by CERT.PL
- 2026-05-22: advisory: NVD record published
- 2026-05-22: patched: Fixed in version 9.5