Year2016 |
MonthAugust |
Reference number20160801 |
Impact areaShore |
Incident locationHouston TX, Atlanta GA, Norfolk VA |
Incident countryUSA |
Victim countryUSA |
Victim identityU.S. ports and 13 organizations’ port authorities and logistics operators worldwide using Navis Webacces. |
Victim TypePort |
MethodSQL injection |
in August 2016, U.S. ports and 13 organizations’ port authorities and logistics operators worldwide using Navis Webacces got hit by a SQL injection. In this attack the hacker released a fully working exploit online without notifying the vendor in advance. The hacker was able to view/ modify/ delete data. In 2016 an ethical hacker "bRpsd" revealed that Navis WebAccess - a web-based app that provides transport operators real-time access to operational logistics information - was highly vulnerable to a critical SQL injection vulnerability. (CVE-2016-5817) A vulnerability that could be exploited by a remote attacker to read or modify data stored in the application’s database. The patch management was well-timed, the software vendor, Navis, was informed about the vulnerability on August 9, just a day after Rpsd published the PoC exploit. Navis released custom patches on August 10.