PT-2019-9715 · Hetronic · Hetronic Nova-M

Akira Urano

+6

·

Publicado

2019-01-04

·

Atualizado

2019-10-09

·

CVE-2018-19023

CVSS v3.1

8.8

Alta

VetorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Hetronic Nova-M versions prior to r161
Description The issue allows for unauthorized replay of a command, spoofing of an arbitrary message, or keeping the controlled load in a permanent "stop" state due to the use of fixed codes that can be reproducible by sniffing and re-transmission.
Recommendations For versions prior to r161, update to version r161 or later to resolve the issue. As a temporary workaround, consider implementing additional authentication or encryption mechanisms to prevent sniffing and re-transmission of commands. Restrict access to the system to minimize the risk of exploitation.

Correção

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-19023
ZDI-19-003

Produtos afetados

Hetronic Nova-M