PT-2020-2068 · Yokogawa · Tristation 1131

Published

2020-04-14

·

Updated

2021-11-08

·

CVE-2020-7483

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions TriStation 1131 versions prior to v4.9.1
Description A vulnerability could cause certain data to be visible on the network when the password feature is enabled. This feature is an additional optional check performed by TS1131 to verify its connection to a specific controller. The data is sent as clear text and is visible on the network. The vulnerability allows a remote attacker to gain unauthorized access to protected information.
Recommendations For versions prior to v4.9.1, consider disabling the password feature until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability, however versions v4.9.1 and later do not have this vulnerability.

Fix

Cleartext Transmission of Sensitive Information

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-01902
CVE-2020-7483

Affected Products

Tristation 1131