← Zuruck zu CVEs
CVE-2019-13553
CRITICAL9.8
Beschreibung
Rittal Chiller SK 3232-Series web interface as built upon Carel pCOWeb firmware A1.5.3 – B1.2.4. The authentication mechanism on affected systems is configured using hard-coded credentials. These credentials could allow attackers to influence the primary operations of the affected systems, namely turning the cooling unit on and off and setting the temperature set point.
CVE Details
CVSS v3.1 Bewertung9.8
SchweregradCRITICAL
CVSS VektorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AngriffsvektorNETWORK
KomplexitatLOW
Erforderliche PrivilegienNONE
BenutzerinteraktionNONE
Veroffentlicht10/25/2019
Zuletzt geandert11/21/2024
Quellenvd
Honeypot-Sichtungen0
Betroffene Produkte
carel:pcoweb_firmwarerittal:chiller_sk_3232
Schwachen (CWE)
CWE-798CWE-798
Referenzen
http://seclists.org/fulldisclosure/2019/Oct/45(ics-cert@hq.dhs.gov)
https://www.us-cert.gov/ics/advisories/icsa-19-297-01(ics-cert@hq.dhs.gov)
http://seclists.org/fulldisclosure/2019/Oct/45(af854a3a-2127-422b-91ae-364da2661108)
https://www.us-cert.gov/ics/advisories/icsa-19-297-01(af854a3a-2127-422b-91ae-364da2661108)
IOC Korrelationen
Keine Korrelationen erfasst
This product uses data from the NVD API but is not endorsed or certified by the NVD.