PT-2022-10182 · Baker Hughes · Baker Hughes Bentley Nevada 3500 System 1 6.X+3

Nicolas Harsey

+1

·

Published

2022-05-25

·

Updated

2022-06-14

·

CVE-2021-32997

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Baker Hughes Bentley Nevada 3500 System 1 6.x versions 6.98 and prior Baker Hughes Bentley Nevada 3500 System 1 versions 21.1 HF1 and prior Baker Hughes Bentley Nevada 3500 Rack Configuration versions 6.4 and prior Baker Hughes Bentley Nevada 3500/22M Firmware versions 5.05 and prior
Description The affected products utilize a weak encryption algorithm for storage and transmission of sensitive data, which may allow an attacker to more easily obtain credentials used for access.
Recommendations For Baker Hughes Bentley Nevada 3500 System 1 6.x versions 6.98 and prior, consider updating to a version that utilizes a stronger encryption algorithm. For Baker Hughes Bentley Nevada 3500 System 1 versions 21.1 HF1 and prior, consider updating to a version that utilizes a stronger encryption algorithm. For Baker Hughes Bentley Nevada 3500 Rack Configuration versions 6.4 and prior, consider updating to a version that utilizes a stronger encryption algorithm. For Baker Hughes Bentley Nevada 3500/22M Firmware versions 5.05 and prior, consider updating to a version that utilizes a stronger encryption algorithm. As a temporary workaround, consider restricting access to sensitive data until a patch is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-32997

Affected Products

Baker Hughes Bentley Nevada 3500 Rack Configuration
Baker Hughes Bentley Nevada 3500 System 1
Baker Hughes Bentley Nevada 3500 System 1 6.X
Baker Hughes Bentley Nevada 3500/22M Firmware