PT-2022-4703 · Cognex · Cognex 3D-A1000 Dimensioning System
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Cognex 3D-A1000 Dimensioning System versions 1.0.3 and prior
Description
The issue is related to missing authentication for critical functions, allowing unauthorized users to change the operator account password via web server commands. This can be achieved by monitoring web socket communications from an unauthenticated session, potentially enabling an attacker to escalate privileges to match those of the compromised account.
Recommendations
For versions 1.0.3 and prior, consider disabling web server commands related to password changes until a patch is available. Restrict access to the web interface to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cognex 3D-A1000 Dimensioning System