PT-2022-3155 · Bently Nevada · Bnmc+1

Daniel Dos Santos

+1

·

Published

2022-06-22

·

Updated

2024-02-09

·

CVE-2022-29952

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Bently Nevada condition monitoring equipment through 2022-04-29
Description The issue is related to the mishandling of authentication in Bently Nevada condition monitoring equipment. It utilizes the TDI command and data protocols for communications between the monitoring controller and System 1 and/or Bently Nevada Monitor Configuration (BNMC) software. These protocols provide configuration management and historical data related functionality. Neither protocol has any authentication features, allowing any attacker capable of communicating with the ports in question to invoke desired functionality. The protocols use ports 60005/TCP and 60007/TCP.
Recommendations For Bently Nevada condition monitoring equipment through 2022-04-29, consider restricting access to ports 60005/TCP and 60007/TCP to minimize the risk of exploitation. As a temporary workaround, consider disabling the TDI command and data protocols until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authentication

Improper Authentication

Weakness Enumeration

Related Identifiers

BDU:2022-03835
CVE-2022-29952

Affected Products

Bnmc
Bently Nevada Condition Monitoring Equipment