PT-2022-3166 · Bristol Babcock+1 · Bristol Babcock 33Xx+1

Published

2022-06-22

·

Updated

2022-06-22

·

CVE-2022-29955

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions ControlWave (affected versions not specified) Bristol Babcock 33xx (affected versions not specified)
Description The issue is related to the implementation of the BSAP/IP protocol in the ControlWave and Bristol Babcock 33xx controllers, which is associated with insufficient encryption resilience. This could allow a remote attacker to disclose protected information.
Recommendations For ControlWave, at the moment, there is no information about a newer version that contains a fix for this vulnerability. For Bristol Babcock 33xx, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Inadequate Encryption Strength

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-03846
CVE-2022-29955

Affected Products

Bristol Babcock 33Xx
Controlwave