Vulnerability record · CVE-2018-9161 · published 31 March 2018
CVE-2018-9161: PrismaWEB checkweigher exposes hardcoded prisma account password in JavaScript file
Prismaindustriale · Checkweigher Prismaweb
Prisma Industriale Checkweigher PrismaWEB 1.21 stores the password for the prismaweb account in a client-readable JavaScript file, user/scripts/login_par.js. Anyone who can reach the web interface can read the file and recover the credentials, which is a hardcoded credentials flaw (CWE-798).
Description
Prisma Industriale Checkweigher PrismaWEB 1.21 allows remote attackers to discover the hardcoded prisma password for the prismaweb account by reading user/scripts/login_par.js.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with unauthenticated network reach, a public exploit and very high EPSS make this an urgent exposure despite the absence of KEV listing.
What it is
Prisma Industriale Checkweigher PrismaWEB 1.21 stores the password for the prismaweb account in a client-readable JavaScript file, user/scripts/login_par.js. Anyone who can reach the web interface can read the file and recover the credentials, which is a hardcoded credentials flaw (CWE-798).
Impact
An attacker obtains valid credentials for the prismaweb account and can log in to the checkweigher web interface with that account's privileges. The CVSS vector rates confidentiality, integrity and availability impact as high, so full control of the device is plausible.
Attack surface
Reachable over the network through the PrismaWEB web interface; the credential file is served to unauthenticated clients, so no authentication or user interaction is required.
Exploitation
A public Exploit-DB entry (44276) exists and EPSS is 0.567 (99th percentile), indicating high predicted exploitation activity; the CVE is not listed in CISA KEV.
What to do
- Upgrade PrismaWEB past 1.21 or apply the vendor's fix; no patched version is named in this record, so confirm with Prisma Industriale.
- If no fix is available, block external access to the checkweigher web interface and restrict it to a trusted management network.
- Change the prismaweb account password and remove or protect user/scripts/login_par.js so credentials are not served to clients.
- Disable or rename the prismaweb account if it is not required for operations.
- Monitor vendor advisories for a firmware update addressing the hardcoded credential.
Detection
- Search web server or proxy logs for requests to user/scripts/login_par.js.
- Alert on successful logins to the PrismaWEB interface from unexpected source IPs or at unusual times.
- Review authentication logs for use of the prismaweb account outside normal maintenance windows.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.exploit-db.com/exploits/44276/ | ExploitThird Party AdvisoryVDB Entry |
| https://www.zeroscience.mk/en/vulnerabilities/ZSL-2018-5453.php | Third Party Advisory |
| https://www.exploit-db.com/exploits/44276/ | ExploitThird Party AdvisoryVDB Entry |
| https://www.zeroscience.mk/en/vulnerabilities/ZSL-2018-5453.php | Third Party Advisory |
Track CVE-2018-9161 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-9161), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.