PT-2022-3155 · Bently Nevada · Bnmc+1
Daniel Dos Santos
+1
·
Published
2022-06-22
·
Updated
2024-02-09
·
CVE-2022-29952
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Bently Nevada condition monitoring equipment through 2022-04-29
Description
The issue is related to the mishandling of authentication in Bently Nevada condition monitoring equipment. It utilizes the TDI command and data protocols for communications between the monitoring controller and System 1 and/or Bently Nevada Monitor Configuration (BNMC) software. These protocols provide configuration management and historical data related functionality. Neither protocol has any authentication features, allowing any attacker capable of communicating with the ports in question to invoke desired functionality. The protocols use ports 60005/TCP and 60007/TCP.
Recommendations
For Bently Nevada condition monitoring equipment through 2022-04-29, consider restricting access to ports 60005/TCP and 60007/TCP to minimize the risk of exploitation. As a temporary workaround, consider disabling the TDI command and data protocols until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Missing Authentication
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Bnmc
Bently Nevada Condition Monitoring Equipment