PT-2017-16855 · Marel Food Processing Systems · V36+30

Publicado

2017-06-30

·

Atualizado

2019-10-09

·

CVE-2017-6041

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Marel Food Processing Systems M3000 terminal Marel Food Processing Systems M3210 terminal Marel Food Processing Systems M3000 desktop software Marel Food Processing Systems MAC4 controller Marel Food Processing Systems SensorX23 X-ray machine Marel Food Processing Systems SensorX25 X-ray machine Marel Food Processing Systems MWS2 weighing system
Description An Unrestricted Upload issue was discovered, allowing an attacker to modify the operation and upload firmware changes without detection. This issue affects various systems, including A320, A325, A371, A520 Master, A520 Slave, A530, A542, A571, Check Bin Grader, FlowlineQC T376, IPM3 Dual Cam v132, IPM3 Dual Cam v139, IPM3 Single Cam v132, P520, P574, SensorX13 QC flow line, SensorX23 QC Master, SensorX23 QC Slave, Speed Batcher, T374, T377, V36, V36B, and V36C.
Recommendations For Marel Food Processing Systems M3000 terminal, consider restricting access to firmware upload functionality until a patch is available. For Marel Food Processing Systems M3210 terminal, consider restricting access to firmware upload functionality until a patch is available. For Marel Food Processing Systems M3000 desktop software, consider restricting access to firmware upload functionality until a patch is available. For Marel Food Processing Systems MAC4 controller, consider restricting access to firmware upload functionality until a patch is available. For Marel Food Processing Systems SensorX23 X-ray machine, consider restricting access to firmware upload functionality until a patch is available. For Marel Food Processing Systems SensorX25 X-ray machine, consider restricting access to firmware upload functionality until a patch is available. For Marel Food Processing Systems MWS2 weighing system, consider restricting access to firmware upload functionality until a patch is available.

Correção

Unrestricted File Upload

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-6041

Produtos afetados

A320
A325
A371
A520 Master
A520 Slave
A530
A542
A571
Check Bin Grader
Flowlineqc T376
Ipm3 Dual Cam V132
Ipm3 Dual Cam V139
Ipm3 Single Cam V132
M3000 Desktop
M3000 Terminal
M3210 Terminal
Mac4 Controller
Mws2 Weighing System
P520
P574
Sensorx13 Qc Flow Line
Sensorx23 Qc Master
Sensorx23 Qc Slave
Sensorx23 X-Ray Machine
Sensorx25 X-Ray Machine
Speed Batcher
T374
T377
V36
V36B
V36C