PT-2017-16855 · Marel Food Processing Systems · V36+30
Published
2017-06-30
·
Updated
2019-10-09
·
CVE-2017-6041
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Marel Food Processing Systems M3000 terminal
Marel Food Processing Systems M3210 terminal
Marel Food Processing Systems M3000 desktop software
Marel Food Processing Systems MAC4 controller
Marel Food Processing Systems SensorX23 X-ray machine
Marel Food Processing Systems SensorX25 X-ray machine
Marel Food Processing Systems MWS2 weighing system
Description
An Unrestricted Upload issue was discovered, allowing an attacker to modify the operation and upload firmware changes without detection. This issue affects various systems, including A320, A325, A371, A520 Master, A520 Slave, A530, A542, A571, Check Bin Grader, FlowlineQC T376, IPM3 Dual Cam v132, IPM3 Dual Cam v139, IPM3 Single Cam v132, P520, P574, SensorX13 QC flow line, SensorX23 QC Master, SensorX23 QC Slave, Speed Batcher, T374, T377, V36, V36B, and V36C.
Recommendations
For Marel Food Processing Systems M3000 terminal, consider restricting access to firmware upload functionality until a patch is available.
For Marel Food Processing Systems M3210 terminal, consider restricting access to firmware upload functionality until a patch is available.
For Marel Food Processing Systems M3000 desktop software, consider restricting access to firmware upload functionality until a patch is available.
For Marel Food Processing Systems MAC4 controller, consider restricting access to firmware upload functionality until a patch is available.
For Marel Food Processing Systems SensorX23 X-ray machine, consider restricting access to firmware upload functionality until a patch is available.
For Marel Food Processing Systems SensorX25 X-ray machine, consider restricting access to firmware upload functionality until a patch is available.
For Marel Food Processing Systems MWS2 weighing system, consider restricting access to firmware upload functionality until a patch is available.
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
A320
A325
A371
A520 Master
A520 Slave
A530
A542
A571
Check Bin Grader
Flowlineqc T376
Ipm3 Dual Cam V132
Ipm3 Dual Cam V139
Ipm3 Single Cam V132
M3000 Desktop
M3000 Terminal
M3210 Terminal
Mac4 Controller
Mws2 Weighing System
P520
P574
Sensorx13 Qc Flow Line
Sensorx23 Qc Master
Sensorx23 Qc Slave
Sensorx23 X-Ray Machine
Sensorx25 X-Ray Machine
Speed Batcher
T374
T377
V36
V36B
V36C