PT-2019-9661 · Controlbyweb · X-320M-I

Published

2019-03-17

·

Updated

2020-08-24

·

CVE-2018-18881

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions ControlByWeb X-320M-I Web-Enabled Instrumentation-Grade Data Acquisition module version 1.05
Description A Denial of Service issue was discovered, allowing an authenticated user to configure invalid network settings. This stops TCP-based communications to the device, requiring a physical factory reset to restore the device to an operational state.
Recommendations For version 1.05, to resolve the issue, a physical factory reset is required to restore the device to an operational state. As a temporary workaround, consider restricting access to network configuration settings to prevent unauthorized changes until a fix is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2018-18881

Affected Products

X-320M-I