← Retour aux CVEs
CVE-2019-13549
HIGH7.5
Description
Rittal Chiller SK 3232-Series web interface as built upon Carel pCOWeb firmware A1.5.3 – B1.2.4. The authentication mechanism on affected systems does not provide a sufficient level of protection against unauthorized configuration changes. Primary operations, namely turning the cooling unit on and off and setting the temperature set point, can be modified without authentication.
Details CVE
Score CVSS v3.17.5
SeveriteHIGH
Vecteur CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Vecteur d'attaqueNETWORK
ComplexiteLOW
Privileges requisNONE
Interaction utilisateurNONE
Publie10/25/2019
Derniere modification11/21/2024
Sourcenvd
Observations honeypot0
Produits affectes
carel:pcoweb_firmwarerittal:chiller_sk_3232
Faiblesses (CWE)
CWE-306CWE-306
References
http://seclists.org/fulldisclosure/2019/Oct/46(ics-cert@hq.dhs.gov)
https://www.us-cert.gov/ics/advisories/icsa-19-297-01(ics-cert@hq.dhs.gov)
http://seclists.org/fulldisclosure/2019/Oct/46(af854a3a-2127-422b-91ae-364da2661108)
https://www.us-cert.gov/ics/advisories/icsa-19-297-01(af854a3a-2127-422b-91ae-364da2661108)
Correlations IOC
Aucune correlation enregistree
This product uses data from the NVD API but is not endorsed or certified by the NVD.