CVE-2009-0216
Last modified
CVE-2009-0216 is a vulnerability of currently unknown severity. GE Fanuc iFIX 5.0 and earlier relies on client-side authentication involving a weakly encrypted local password file, which allows remote attackers to bypass intended access restrictions and start privileged server login sessions by recovering a password or by using a modified program module.. EPSS estimates a 2.98% chance of exploitation in the next 30 days.
Description
GE Fanuc iFIX 5.0 and earlier relies on client-side authentication involving a weakly encrypted local password file, which allows remote attackers to bypass intended access restrictions and start privileged server login sessions by recovering a password or by using a modified program module.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ge Fanuc | Ifix | <= 5.0 |
| Ge Fanuc | Ifix | 2.0 |
| Ge Fanuc | Ifix | 2.2 |
| Ge Fanuc | Ifix | 2.5 |
| Ge Fanuc | Ifix | 2.6 |
| Ge Fanuc | Ifix | 2.21 |
| Ge Fanuc | Ifix | 3.0 |
| Ge Fanuc | Ifix | 3.5 |
| Ge Fanuc | Ifix | 4.0 |
| Ge Fanuc | Ifix | 4.5 |
References
- http://www.kb.cert.org/vuls/id/310355US Government Resource
- http://www.kb.cert.org/vuls/id/310355US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2009-0216?
How severe is CVE-2009-0216?
How do I fix CVE-2009-0216?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2009
- CVE-2009-0210Buffer overflow in the MLF application in AREVA e-terrahabit…
- CVE-2009-0211Unspecified vulnerability in the WebFGServer application in …
- CVE-2009-0212Unspecified vulnerability in the WebFGServer application in …
- CVE-2009-0213Unspecified vulnerability in the NETIO application in AREVA …
- CVE-2009-0214Unspecified vulnerability in the WebFGServer application in …
- CVE-2009-0215Stack-based buffer overflow in the GetXMLValue method in the…
- CVE-2009-0217The design of the W3C XML Signature Syntax and Processing (X…
- CVE-2009-0218Insecure method vulnerability in Particle Software IntraLaun…
- CVE-2009-0219The PDF distiller in the Attachment Service in Research in M…
- CVE-2009-0220Multiple stack-based buffer overflows in the PowerPoint 4.0 …
- CVE-2009-0221Integer overflow in Microsoft Office PowerPoint 2002 SP3 and…
- CVE-2009-0222Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3…
Are you affected by CVE-2009-0216?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
