PT-2021-22879 · Unknown · Climatix Pol909

Published

2021-11-09

·

Updated

2022-08-09

·

CVE-2021-40366

CVSS v3.1

7.4

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Climatix POL909 (AWB module) versions prior to V11.42 Climatix POL909 (AWM module) versions prior to V11.34
Description A vulnerability has been identified where the web server of affected devices transmits data without TLS encryption. This could allow an unauthenticated remote attacker in a man-in-the-middle position to read sensitive data, such as administrator credentials, or modify data in transit.
Recommendations For Climatix POL909 (AWB module) versions prior to V11.42, update to version V11.42 or later to resolve the issue. For Climatix POL909 (AWM module) versions prior to V11.34, update to version V11.34 or later to resolve the issue.

Fix

Cleartext Transmission of Sensitive Information

Missing Encryption of Sensitive Data

Weakness Enumeration

Related Identifiers

CVE-2021-40366

Affected Products

Climatix Pol909