Rittal Chiller SK 3232-Series web interface as built upon Carel pCOWeb firmware A1.5.3 – B1.2.4. The authentication mechanism on affected systems does not provide a sufficient level of protection against unauthorized configuration changes. Primary operations, namely turning the cooling unit on and off and setting the temperature set point, can be modified without authentication.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NCarel Pcoweb Firmware
OSCarela1.5.3 – b1.2.4Rittal Chiller Sk 3232
HWRittalall versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Related vulnerabilities
CVE-2019-13553CRITICAL9.8PL ✓same product
Hardcoded credentials w Rittal Chiller SK 3232 / Carel pCOWeb
CVE-2024-47945CRITICAL9.8PL ✓same vendor
Przewidywalne identyfikatory sesji w urządzeniach Rittal IoT Interface i CMC III
CVE-2022-34827CRITICAL9.9PL ✓same vendor
Nieprawidłowa kontrola dostępu w Carel Boss Mini 1.5.0
CVE-2020-11951CRITICAL9.8PL ✓same vendor
Ukryte konto backdoor root w urządzeniach Rittal PDU i CMCIII
CVE-2020-11956CRITICAL9.8PL ✓same vendor
Naruszenie zasady minimalnych uprawnień w urządzeniach Rittal PDU i CMCIII