PT-2021-22879 · Unknown · Climatix Pol909
Published
2021-11-09
·
Updated
2022-08-09
·
CVE-2021-40366
CVSS v3.1
7.4
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Climatix POL909 (AWB module) versions prior to V11.42
Climatix POL909 (AWM module) versions prior to V11.34
Description
A vulnerability has been identified where the web server of affected devices transmits data without TLS encryption. This could allow an unauthenticated remote attacker in a man-in-the-middle position to read sensitive data, such as administrator credentials, or modify data in transit.
Recommendations
For Climatix POL909 (AWB module) versions prior to V11.42, update to version V11.42 or later to resolve the issue.
For Climatix POL909 (AWM module) versions prior to V11.34, update to version V11.34 or later to resolve the issue.
Fix
Cleartext Transmission of Sensitive Information
Missing Encryption of Sensitive Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Climatix Pol909