PT-2023-15973 · Sauter · Sauter Controls Nova 200–220 Series
Aarón Flecha Menéndez
+2
·
Published
2023-01-16
·
Updated
2023-10-27
·
CVE-2023-0053
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
SAUTER Controls Nova 200–220 Series versions 3.3-006 and prior
BACnetstac versions 4.2.1 and prior
Description
The issue affects device management, where sensitive information such as credentials is sent in cleartext through FTP and Telnet protocols. An attacker could obtain this sensitive information to gain access to the system.
Recommendations
For SAUTER Controls Nova 200–220 Series versions 3.3-006 and prior, consider disabling the use of FTP and Telnet protocols for device management until a secure alternative is available.
For BACnetstac versions 4.2.1 and prior, restrict access to the system using FTP and Telnet to minimize the risk of exploitation.
As a temporary workaround, avoid using cleartext protocols for communicating sensitive information, such as credentials, until a patch or secure alternative is available.
Fix
Cleartext Transmission of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sauter Controls Nova 200–220 Series