Full Disclosure mailing list archives
Re: Security advisory: multiple vulnerabilities including Default-credential RCE, Pre-authentication root RCE in atvise SCADA 3.13.0 (atvise GmbH / Bachmann Visutec)
From: "LOMOSITS.Daniel via Fulldisclosure" <fulldisclosure () seclists org>
Date: Mon, 17 Aug 2026 11:42:44 +0000
Reference: https://seclists.org/fulldisclosure/2026/Aug/5 I tested both vulnerabilities against a clean installation of atvise SCADA 3.13.0. Results differ between the two findings. --- Vulnerability 1 (OPC UA pre-authentication root RCE, CVSS 9.8) - NOT REPRODUCIBLE The ActivateSession step - identified as the authentication bypass entry point - returns BadUserAccessDenied: WebMI login(root, bogus) -> 200 {"error":-1,"errorstring":"Invalid Session or Digest"} [+] root has a strong password (bogus login rejected) [Step 1] OPC UA 4840 ActivateSession(root, bogus) -- authentication bypass ServiceFault (BadUserAccessDenied, diagnostics: DiagnosticInfo( SymbolicId=None, NamespaceURI=None, Locale=None, LocalizedText=None, AdditionalInfo=None, InnerStatusCode=None, InnerDiagnosticInfo=None)) from server received in response to ActivateSessionRequest The OPC UA backend rejects the bogus password and does not yield a superuser session, contrary to the advisory's claim that logonSessionUser never calls the password-verification function. Note for anyone attempting independent reproduction: the advisory's license note discloses that the research was conducted against a binary-patched installation (patch 5: isLicensed() forced to 1; patch 6: session-count bypass). Whether OPC UA authentication behaviour differs between the patched binary and an unmodified licensed installation remains the open question. If the 0day Rubbish Research Team can clarify whether the ActivateSession step was verified against the original unpatched binary, that would help resolve the discrepancy. --- Vulnerability 2 (WebMI default-credential RCE, CVSS 8.8) - REPRODUCIBLE Confirmed. login(root, <any value>) returns {"username":"root"} on a factory-default installation. The handleLogin 'password not set' branch behaves exactly as described. Setting a strong root password via changepassword closes the bypass. Mit freundlichen Grüßen With kind regards Ing. Daniel Lomosits MSc MBA BSc Product Manager P +43 (0)2682 / 75799-2829 M +43 (0) 676 / 702 80 87 | daniel.lomosits () bachmann info<mailto:daniel.lomosits () bachmann info> | www.bachmann-visutec.com<http://www.bachmann-visutec.com/> [cid:image001.png@01DD2E3D.5EAA1330]<https://atvise.com/> Registered Office: Bachmann Visutec GmbH, Kasernenstraße 29, 7000 Eisenstadt, Austria FN 274018v Commercial Register Eisenstadt | ATU 62240738 Corporate Headquarters: Bachmann electronic GmbH, Kreuzäckerweg 33, 6800 Feldkirch, Austria FN 75348g Commercial Register Feldkirch | ATU 36410905 Dokumente mit rechtsverbindlichem Inhalt sind nur mit Originalunterschrift wirksam. Documents with legally binding subject matter are valid only with original hand-written signature. Follow Bachmann on Facebook<https://www.facebook.com/Bachmann.electronic/> | LinkedIn<https://www.linkedin.com/company/bachmann-electronic-gmbh> | Twitter<https://twitter.com/bachmann_corp> | Xing<https://www.xing.com/companies/bachmannelectronicgmbh> | YouTube<https://www.youtube.com/channel/UCE5LllKmEA5ZtBnsIpvVqxg>
_______________________________________________ Sent through the Full Disclosure mailing list https://nmap.org/mailman/listinfo/fulldisclosure Web Archives & RSS: https://seclists.org/fulldisclosure/
Current thread:
- Security advisory: multiple vulnerabilities including Default-credential RCE, Pre-authentication root RCE in atvise SCADA 3.13.0 (atvise GmbH / Bachmann Visutec) disclosure via Fulldisclosure (Aug 06)
- <Possible follow-ups>
- Re: Security advisory: multiple vulnerabilities including Default-credential RCE, Pre-authentication root RCE in atvise SCADA 3.13.0 (atvise GmbH / Bachmann Visutec) LOMOSITS.Daniel via Fulldisclosure (Aug 17)

