A series of vulnerabilities exist in a popular web-based SCADA system made by Honeywell that make it easy to expose passwords and in turn, give attackers a foothold into the vulnerable network. The flaws exist in some versions of Honeywell s XL Web II controllers, systems deployed across the critical infrastructure sector, including wastewater, energy, and manufacturing companies. The company has developed a fix, version 3.04.05, to address the issues but users have to call their local Honeywell Building Solutions branch to receive the update.
Source: https://threatpost.com/honeywell-scada-controllers-exposed-passwords-in-clear-text/123562/

