Exploitation Summary
EIP tracks 1 public exploit for CVE-2016-8366. PoCs published by Photubias.
AI-analyzed exploit summary This exploit retrieves clear-text credentials and SHA256 password hashes from Phoenix Contact WebVisit GUI by parsing hex-encoded data in the application's response. It targets a password disclosure vulnerability in versions prior to 6.40.00.
Description
Webvisit in Phoenix Contact ILC PLCs offers a password macro to protect HMI pages on the PLC against casual or coincidental opening of HMI pages by the user. The password macro can be configured in a way that the password is stored and transferred in clear text.
Exploits (1)
This exploit retrieves clear-text credentials and SHA256 password hashes from Phoenix Contact WebVisit GUI by parsing hex-encoded data in the application's response. It targets a password disclosure vulnerability in versions prior to 6.40.00.
References (3)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L