PT-2022-18490 · Kingspan · Kingspan Tms300 Cs
Maxim Rupp
·
Published
2022-09-19
·
Updated
2022-12-16
·
CVE-2022-2757
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Kingspan TMS300 CS versions (affected versions not specified)
Description
The issue is due to the lack of adequately implemented access-control rules, allowing an attacker to view and modify application settings without authenticating by accessing a specific uniform resource locator (URL) on the webserver. This can be done by accessing certain URLs, which can be set through the web interface or using brute force. The attacker can change various settings, including those related to sensors, tank information, and alarm threshold values, potentially leading to an emergency situation. The vulnerable product is used worldwide in the water supply and drainage sector.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kingspan Tms300 Cs