Rittal Chiller SK 3232-Series web interface as built upon Carel pCOWeb firmware A1.5.3 – B1.2.4. The authentication mechanism on affected systems does not provide a sufficient level of protection against unauthorized configuration changes. Primary operations, namely turning the cooling unit on and off and setting the temperature set point, can be modified without authentication.
oryginał ENCVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NCarel Pcoweb Firmware
OSCarela1.5.3 – b1.2.4Rittal Chiller Sk 3232
HWRittalwszystkie wersje
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Powiązane podatności
CVE-2019-13553CRITICAL9.8PL ✓ten sam produkt
Hardcoded credentials w Rittal Chiller SK 3232 / Carel pCOWeb
CVE-2024-47945CRITICAL9.8PL ✓ten sam vendor
Przewidywalne identyfikatory sesji w urządzeniach Rittal IoT Interface i CMC III
CVE-2022-34827CRITICAL9.9PL ✓ten sam vendor
Nieprawidłowa kontrola dostępu w Carel Boss Mini 1.5.0
CVE-2020-11951CRITICAL9.8PL ✓ten sam vendor
Ukryte konto backdoor root w urządzeniach Rittal PDU i CMCIII
CVE-2020-11956CRITICAL9.8PL ✓ten sam vendor
Naruszenie zasady minimalnych uprawnień w urządzeniach Rittal PDU i CMCIII