PT-2022-3165 · Bristol Babcock+1 · Bristol Babcock 33Xx+1

Published

2022-06-22

·

Updated

2022-06-22

·

CVE-2022-29954

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions ControlWave (affected versions not specified) Bristol Babcock 33xx (affected versions not specified)
Description The issue is related to the implementation of the BSAP/IP protocol in the ControlWave and Bristol Babcock 33xx controllers, which involves the transmission of critical information in plain text. This could allow a remote attacker to disclose protected information.
Recommendations For ControlWave, at the moment, there is no information about a newer version that contains a fix for this issue. For Bristol Babcock 33xx, at the moment, there is no information about a newer version that contains a fix for this issue.

Fix

Cleartext Transmission of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-03845
CVE-2022-29954

Affected Products

Bristol Babcock 33Xx
Controlwave