PT-2019-13416 · Rittal · Rittal Chiller Sk 3232-Series
Published
2019-10-25
·
Updated
2020-02-10
·
CVE-2019-13553
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Rittal Chiller SK 3232-Series versions A1.5.3 through B1.2.4
Description
The issue concerns the authentication mechanism in the web interface of the affected systems, which uses hard-coded credentials. This could allow attackers to influence primary operations, including turning the cooling unit on and off and setting the temperature set point.
Recommendations
For versions A1.5.3 through B1.2.4, consider changing the hard-coded credentials to unique, secure credentials to prevent unauthorized access. As a temporary workaround, restrict access to the web interface to minimize the risk of exploitation.
Fix
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rittal Chiller Sk 3232-Series