CVE-2009-4463 describes a critical vulnerability in Intellicom NetBiter WebSCADA devices, specifically affecting the netbiter_webscada_firmware, WS100, and WS200 models. The vulnerability stems from the use of default passwords for the HICP network configuration service, allowing remote attackers to modify network settings and potentially cause a denial of service. This vulnerability carries a CVSS score of 10.0, indicating maximum severity due to its network-based attack vector, low attack complexity, and complete compromise of confidentiality, integrity, and availability. While the issue is present only when administrators fail to change default passwords, its potential impact is severe. Currently, there is no evidence of active exploitation, and no public exploit code is available on platforms like Metasploit, Nuclei, or ExploitDB. The vulnerability has received minimal community attention, with no social media discussions or media coverage reported.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.11.0CPE matchmatch criteria | cpe:2.3:h:intellicom:netbiter_webscada_firmware:3.11.0:*:*:*:*:*:*:* | ||
3.11.1CPE matchmatch criteria | cpe:2.3:h:intellicom:netbiter_webscada_firmware:3.11.1:*:*:*:*:*:*:* | ||
3.11.2CPE matchmatch criteria | cpe:2.3:h:intellicom:netbiter_webscada_firmware:3.11.2:*:*:*:*:*:*:* | ||
3.12.4CPE matchmatch criteria | cpe:2.3:h:intellicom:netbiter_webscada_firmware:3.12.4:*:*:*:*:*:*:* | ||
3.12.6CPE matchmatch criteria | cpe:2.3:h:intellicom:netbiter_webscada_firmware:3.12.6:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.