Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2023-3350 — Exploit for cryptographic Issue vulnerability on IBERMATICA RPS [CVE-2023-3350] | Kitploit
Tools/GitHubGitHub/itres-labs/cve-2023-3350
Vulnerability AnalysisExploitationWeb Application ExploitationInformation GatheringCryptographyPenetration TestingPapers & ResearchLearning & EducationRed Teaming
GitHubitres-labs/cve-2023-3350

CVE-2023-3350

Exploit for cryptographic Issue vulnerability on IBERMATICA RPS [CVE-2023-3350]

132 months agoNot yet reviewed
View RepositoryWebsite

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2023-3349 / CVE-2023-3350 | IBERMATICA RPS 2019

Security research documenting an unauthenticated information disclosure and a cryptographic design flaw in IBERMATICA RPS 2019.

The vulnerabilities can be chained to expose application logs containing authentication-related SQL queries and recover user passwords from reversible AES-CBC ciphertext.

[DISCLAIMER] This repository is provided for security research, defensive validation, and educational purposes only. Test exclusively on systems you own or are explicitly authorized to assess.

Summary

An unauthenticated user can access the RPS service status page at:

/RPS2019Service/status.html

The page exposes operational logging controls and allows generated logs to be downloaded. These logs may contain sensitive application data, including usernames, IP addresses, SQL queries, and password-related values.

Passwords are not protected with a one-way password hashing function. Instead, RPS 2019 uses AES-128-CBC with keying material derived predictably from the username. Once a username and its encrypted password value are obtained from the logs, the password can be recovered in plaintext.

Vulnerabilities

CVEDescriptionCWECVSS 3.1 (CNA)
CVE-2023-3349Unauthenticated exposure of sensitive information through downloadable application logsCWE-2008.2 High
CVE-2023-3350Reversible password protection based on AES-128-CBC and predictable username-derived keying materialCWE-3278.2 High

Affected product

  • Product: IBERMATICA RPS
  • Affected version: RPS 2019
  • Component: RPS 2019 Service status and logging functionality

Attack chain

  1. Access the exposed RPS status page without authentication.
  2. Enable application logging through the available status-page controls.
  3. Trigger or wait for authentication activity.
  4. Download the generated log file.
  5. Extract usernames and encrypted password values from logged SQL queries.
  6. Derive the AES keying material from the corresponding username.
  7. Decrypt the stored value and recover the password in plaintext.

No SQL injection, password brute force, or prior application account is required for this chain.

Technical notes

The investigation identified the following conditions:

  • Debug logs contain complete SQL queries related to authentication.
  • Login attempts for nonexistent usernames may log the supplied password in plaintext.
  • Existing-user passwords appear as Base64-encoded ciphertext in SQL queries.
  • The encryption scheme uses AES-128 in CBC mode.
  • The key and initialization vector are deterministically derived from the username and padded to 16 bytes with a fixed character.
  • The same predictable value is used as both key and IV.

AES is not the underlying problem by itself. The vulnerability results from using reversible encryption for passwords, predictable keying material, and an IV that is neither random nor independent.

Impact

Successful exploitation may allow a remote, unauthenticated attacker to:

  • retrieve sensitive operational and application information;
  • enumerate valid usernames and infrastructure details;
  • obtain plaintext passwords;
  • compromise privileged RPS accounts;
  • reuse exposed credentials against other services where passwords have been shared.

Remediation and hardening

  • Apply the vendor-provided update or mitigation for RPS 2019.
  • Remove public access to /RPS2019Service/status.html.
  • Require strong authentication and authorization for all diagnostic, administrative, status, health, debug, and metrics endpoints.
  • Disable production debug logging when it is not strictly required.
  • Redact credentials, authentication data, and complete SQL queries from logs.
  • Store passwords with a modern, salted, one-way password hashing function such as Argon2id, scrypt, or bcrypt.
  • Rotate all credentials that may have appeared in affected logs.
  • Review historical access logs for requests to the status page and log downloads.
  • Prevent direct Internet exposure of ERP management and support interfaces.

Detection opportunities

Defenders should investigate:

  • unexpected requests to /RPS2019Service/status.html;
  • requests that enable, stop, delete, or download application logs;
  • access to status or diagnostic endpoints from untrusted networks;
  • unusual authentication events following access to RPS log files;
  • reuse of RPS credentials against other internal or external services.

Disclosure

The issues were discovered by LABS @ ITRES during an authorized offensive security engagement and were assigned CVE identifiers through INCIBE-CERT.

A detailed technical write-up is available in the first entry of the Old Dives series:

  • Old Dives #01: The RPS Status Page That Gave Passwords Back

References

  • CVE-2023-3349 — NVD
  • CVE-2023-3350 — NVD
  • Multiple vulnerabilities in IBERMATICA RPS 2019 — INCIBE-CERT
  • LABS @ ITRES

Legal notice

The information in this repository is intended to help organizations identify, validate, and remediate the documented vulnerabilities. The authors and contributors are not responsible for misuse or damage resulting from the use of this material.

Download Tool