## 1. EXECUTIVE SUMMARY
* **âCVSS v3 9.8**
* **âATTENTION: **Exploitable remotely/low attack complexity
* **âVendor: **Weintek
* **âEquipment: **Weincloud
* **âVulnerabilities: **Weak Password Recovery Mechanism for Forgotten Password, Improper Authentication, Improper Restriction of Excessive Authentication Attempts, Improper Handling of Structural Elements
## 2. RISK EVALUATION
âSuccessful exploitation of these vulnerabilities could allow an attacker to utilize the JSON web token (JWT) to reset account passwords, use expired credentials, perform brute force attacks on credentials, or cause a denial-of-service condition.
## 3. TECHNICAL DETAILS
### 3.1 AFFECTED PRODUCTS
âThe following Weintek Weincloud versions are affected:
* âAccount API: Versions 0.13.6 and prior
### 3.2 VULNERABILITY OVERVIEW
**3.2.1 â[WEAK PASSWORD RECOVERY MECHANISM FOR FORGOTTEN PASSWORD CWE-640]()**
âThe affected product could allow an attacker to reset a password with the corresponding accountâs JWT token only.
â[CVE-2023-35134]() has been assigned to this vulnerability. A CVSS v3 base score of 7.4 has been calculated; the CVSS vector string is ([AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N]()).
**3.2.2 â[IMPROPER AUTHENTICATION CWE-287]()**
âThe affected product could allow an attacker to abuse the registration functionality to login with testing credentials to the official website.
â[CVE-2023-37362]() has been assigned to this vulnerability. A CVSS v3 base score of 7.2 has been calculated; the CVSS vector string is ([AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H]()).
**3.2.3 â[IMPROPER RESTRICTION OF EXCESSIVE AUTHENTICATION ATTEMPTS CWE-307]()**
âThe affected product could allow an attacker to efficiently develop a brute force attack on credentials with authentication hints from error message responses.
â[CVE-2023-32657]() has been assigned to this vulnerability. A CVSS v3 base score of 5.3 has been calculated; the CVSS vector string is ([AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N]()).
**3.2.4 â[IMPROPER HANDLING OF STRUCTURAL ELEMENTS CWE-237]()**
âThe affected product could allow an attacker to cause a denial-of-service condition for Weincloud by sending a forged JWT token.
â[CVE-2023-34429]() has been assigned to this vulnerability. A CVSS v3 base score of 7.5 has been calculated; the CVSS vector string is ([AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H]()).
### 3.3 BACKGROUND
* **âCRITICAL INFRASTRUCTURE SECTORS: **Critical Manufacturing
* **âCOUNTRIES/AREAS DEPLOYED: **Worldwide
* **âCOMPANY HEADQUARTERS LOCATION:** Taiwan
### 3.4 RESEARCHER
âHank Chen (PSIRT and Threat Research of TXOne Networks) reported these vulnerabilities to CISA.
## 4. MITIGATIONS
âWeintek has updated their account API to v0.13.8, which has fixed the issue. This fix does not require any action for users.
âAdditional mitigations are recommended to help reduce risk:
* âLog in on trusted computers if possible. Log out after usage on un-trusted ones.
* âOn the HMIs, if the online services are not used, set to offline mode for EasyAccess 2.0 or Dashboard services using system reserved addresses.
* âRegularly change passwords to reduce risks.
* âMinimize network exposure for all control system devices and/or systems, and ensure they are not accessible- only applicable devices and/or systems have access to the internet.
âCISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities. Specifically, users should:
* âLocate control system networks and remote devices behind firewalls and isolate them from business networks.
* âWhen remote access is required, use secure methods, such as virtual private networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as its connected devices.
âCISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.
âCISA also provides a section for [control systems security recommended practices]() on the ICS webpage at [cisa.gov/ics](). Several CISA products detailing cyber defense best practices are available for reading and download, including [Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies]().
âAdditional mitigation guidance and recommended practices are publicly available on the ICS webpage at [cisa.gov/ics]() in the technical information paper, [ICS-TIP-12-146-01B–Targeted Cyber Intrusion Detection and Mitigation Strategies]().
âOrganizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.
âNo known public exploits specifically target these vulnerabilities.Read More