PT-2019-13412 · Rittal · Rittal Chiller Sk 3232-Series

Publicado

2019-10-25

·

Atualizado

2020-02-10

·

CVE-2019-13549

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Rittal Chiller SK 3232-Series versions A1.5.3 through B1.2.4
Description The issue concerns the authentication mechanism in the web interface of the affected systems, which does not provide sufficient protection against unauthorized configuration changes. This allows primary operations, such as turning the cooling unit on and off and setting the temperature set point, to be modified without authentication.
Recommendations For versions A1.5.3 through B1.2.4, consider restricting access to the web interface until a fix is available, and ensure that physical access to the device is controlled to prevent unauthorized changes. As a temporary workaround, limit the use of the web interface for configuration changes and rely on alternative, more secure methods for managing the device.

Correção

Missing Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-13549

Produtos afetados

Rittal Chiller Sk 3232-Series