PT-2020-11212 · Auto Maskin · Marine Observer Pro+2
Published
2020-03-23
·
Updated
2020-03-25
·
CVE-2019-6560
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Auto-Maskin RP210E versions 3.7 and prior
DCU210E versions 3.7 and prior
Marine Observer Pro (Android App) (affected versions not specified)
Description
The software contains a weak mechanism for users to recover or change their passwords without knowing the original password.
Recommendations
For Auto-Maskin RP210E versions 3.7 and prior, consider disabling the password recovery mechanism until a stronger mechanism is implemented.
For DCU210E versions 3.7 and prior, consider disabling the password recovery mechanism until a stronger mechanism is implemented.
For Marine Observer Pro (Android App), at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Auto-Maskin Rp210E
Dcu210E
Marine Observer Pro