CVE-2020-37143
7.5GE Intelligent Platforms · ProficySCADA
ProficySCADA for iOS version 5.0.25920 is susceptible to a denial of service vulnerability triggered by providing an excessively long string to the password input field.
Executive summary
A denial of service vulnerability in GE Intelligent Platforms ProficySCADA for iOS allows an attacker to crash the application, resulting in a loss of service for authorized users.
Vulnerability
The application fails to properly limit the resources allocated to the password input field, allowing an unauthenticated attacker to trigger a crash by submitting 257 bytes of repeated characters. This flaw resides in the authentication process and leads to a resource exhaustion state.
Business impact
The ability to remotely or locally crash the SCADA interface can significantly impede operational visibility and control, leading to potential downtime for critical monitoring systems. While the CVSS score of 7.5 indicates a high technical severity, the impact is primarily focused on availability rather than data compromise, though the interruption of industrial oversight poses a substantial risk to business continuity.
Remediation
Immediate Action: As no official patch is documented, users should restrict access to the device and monitor for potential crash events until the vendor provides a formal update.
Proactive Monitoring: Security teams should monitor device logs for unexpected application termination events or repeated authentication failures that may indicate an attempt to trigger this crash.
Compensating Controls: Ensure that mobile device management policies are in place to limit unauthorized access to the application, and consider using endpoint security solutions capable of detecting abnormal application behavior.
Exploitation status
Public Exploit Available: Yes, a proof of concept is available via the Exploit Database (EDB-ID 48236).
Analyst recommendation
Given the availability of a public proof of concept and the critical nature of SCADA software, this vulnerability represents a credible risk to availability. Organizations utilizing this application should prioritize limiting its exposure to untrusted users and contact the vendor for confirmation regarding the availability of a security update or a hardened version of the software.
Sources
Originally found and disclosed by Ivan Marmolejo, per the CVE Program record.
- ExploitDB-48236 Exploit / PoC
- Archived App Software
- VulnCheck Advisory: ProficySCADA for iOS 5.0.25920 - 'Password' Denial of Service Third-party advisory