PT-2019-18140 · Unknown · Modbus Gateway
CVE-2019-6527
·
Publicado
2019-02-12
·
Atualizado
2023-01-31
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Modbus gateway versions prior to Release R02 (or Software Version 1.1.13166)
Description
The issue allows an attacker to change the password for an admin user who is currently or previously logged in, provided the device has not been restarted.
Recommendations
For Modbus gateway versions prior to Release R02 (or Software Version 1.1.13166), update to Release R02 or Software Version 1.1.13166 or later to resolve the issue.
Correção
Improper Authentication
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Modbus Gateway