
Exploit for cryptographic Issue vulnerability on IBERMATICA RPS [CVE-2023-3350]
Security research documenting an unauthenticated information disclosure and a cryptographic design flaw in IBERMATICA RPS 2019.
The vulnerabilities can be chained to expose application logs containing authentication-related SQL queries and recover user passwords from reversible AES-CBC ciphertext.
[DISCLAIMER] This repository is provided for security research, defensive validation, and educational purposes only. Test exclusively on systems you own or are explicitly authorized to assess.
An unauthenticated user can access the RPS service status page at:
/RPS2019Service/status.html
The page exposes operational logging controls and allows generated logs to be downloaded. These logs may contain sensitive application data, including usernames, IP addresses, SQL queries, and password-related values.
Passwords are not protected with a one-way password hashing function. Instead, RPS 2019 uses AES-128-CBC with keying material derived predictably from the username. Once a username and its encrypted password value are obtained from the logs, the password can be recovered in plaintext.
| CVE | Description | CWE | CVSS 3.1 (CNA) |
|---|---|---|---|
| CVE-2023-3349 | Unauthenticated exposure of sensitive information through downloadable application logs | CWE-200 | 8.2 High |
| CVE-2023-3350 | Reversible password protection based on AES-128-CBC and predictable username-derived keying material | CWE-327 | 8.2 High |
No SQL injection, password brute force, or prior application account is required for this chain.
The investigation identified the following conditions:
AES is not the underlying problem by itself. The vulnerability results from using reversible encryption for passwords, predictable keying material, and an IV that is neither random nor independent.
Successful exploitation may allow a remote, unauthenticated attacker to:
/RPS2019Service/status.html.Defenders should investigate:
/RPS2019Service/status.html;The issues were discovered by LABS @ ITRES during an authorized offensive security engagement and were assigned CVE identifiers through INCIBE-CERT.
A detailed technical write-up is available in the first entry of the Old Dives series:
The information in this repository is intended to help organizations identify, validate, and remediate the documented vulnerabilities. The authors and contributors are not responsible for misuse or damage resulting from the use of this material.