PT-2021-19218 · Bf-430+3 · Bf-430+3
Sirpedrotavares
·
Published
2021-06-04
·
Updated
2021-06-08
·
CVE-2021-31251
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
BF-430 and BF431 232/422 TCP/IP Converter versions (affected versions not specified)
BF-450M versions (affected versions not specified)
SEMAC versions (affected versions not specified)
Description
An authentication bypass in the telnet server allows obtaining a privileged connection with the target device by supplying a specially malformed request. An attacker may force the remote telnet server to believe that the user has already authenticated.
Recommendations
For BF-430 and BF431 232/422 TCP/IP Converter, consider disabling the telnet server until a patch is available.
For BF-450M, restrict access to the telnet server to minimize the risk of exploitation.
For SEMAC, avoid using the telnet server until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bf-430
Bf-450M
Bf431 232/422 Tcp/Ip Converter
Semac