PT-2022-10182 · Baker Hughes · Baker Hughes Bentley Nevada 3500 System 1 6.X+3
Nicolas Harsey
+1
·
Published
2022-05-25
·
Updated
2022-06-14
·
CVE-2021-32997
CVSS v3.1
8.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Baker Hughes Bentley Nevada 3500 System 1 6.x versions 6.98 and prior
Baker Hughes Bentley Nevada 3500 System 1 versions 21.1 HF1 and prior
Baker Hughes Bentley Nevada 3500 Rack Configuration versions 6.4 and prior
Baker Hughes Bentley Nevada 3500/22M Firmware versions 5.05 and prior
Description
The affected products utilize a weak encryption algorithm for storage and transmission of sensitive data, which may allow an attacker to more easily obtain credentials used for access.
Recommendations
For Baker Hughes Bentley Nevada 3500 System 1 6.x versions 6.98 and prior, consider updating to a version that utilizes a stronger encryption algorithm.
For Baker Hughes Bentley Nevada 3500 System 1 versions 21.1 HF1 and prior, consider updating to a version that utilizes a stronger encryption algorithm.
For Baker Hughes Bentley Nevada 3500 Rack Configuration versions 6.4 and prior, consider updating to a version that utilizes a stronger encryption algorithm.
For Baker Hughes Bentley Nevada 3500/22M Firmware versions 5.05 and prior, consider updating to a version that utilizes a stronger encryption algorithm.
As a temporary workaround, consider restricting access to sensitive data until a patch is available.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Baker Hughes Bentley Nevada 3500 Rack Configuration
Baker Hughes Bentley Nevada 3500 System 1
Baker Hughes Bentley Nevada 3500 System 1 6.X
Baker Hughes Bentley Nevada 3500/22M Firmware