PT-2023-15973 · Sauter · Sauter Controls Nova 200–220 Series

Aarón Flecha Menéndez

+2

·

Published

2023-01-16

·

Updated

2023-10-27

·

CVE-2023-0053

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions SAUTER Controls Nova 200–220 Series versions 3.3-006 and prior BACnetstac versions 4.2.1 and prior
Description The issue affects device management, where sensitive information such as credentials is sent in cleartext through FTP and Telnet protocols. An attacker could obtain this sensitive information to gain access to the system.
Recommendations For SAUTER Controls Nova 200–220 Series versions 3.3-006 and prior, consider disabling the use of FTP and Telnet protocols for device management until a secure alternative is available. For BACnetstac versions 4.2.1 and prior, restrict access to the system using FTP and Telnet to minimize the risk of exploitation. As a temporary workaround, avoid using cleartext protocols for communicating sensitive information, such as credentials, until a patch or secure alternative is available.

Fix

Cleartext Transmission of Sensitive Information

Weakness Enumeration

Related Identifiers

CVE-2023-0053

Affected Products

Sauter Controls Nova 200–220 Series