CRITICAL🇵🇱 Wersja polska

CVE-2024-43423

CVSS 9.3v4.0pub. 2024-09-25upd. 2024-10-01

The web application for ProGauge MAGLINK LX4 CONSOLE contains an administrative-level user account with a password that cannot be changed.

🤖 AI Analysis
How it works

The manufacturer embedded an administrative account with a hard-coded password in the firmware that cannot be changed by the administrator or system user. This type of vulnerability (CWE-259, CWE-798) means that the password is identical across all device instances. An attacker who learns this password—for example, through firmware analysis or from publicly available sources—can freely log into the administrative panel over the network without requiring any prior privileges.

Impact

An attacker gains full administrative access to the console managing the fuel measurement system, which may enable manipulation of measurement data, modification of device configuration, or disruption of fuel station infrastructure operations.

Mitigation & patch

Apply patches available from the manufacturer in accordance with the references (CISA ICS advisory ICSA-24-268-04). Until updates are applied, it is recommended to isolate devices from the public network, restrict network access to the web panel to trusted IP addresses only, and monitor access logs for unauthorized login attempts.

Who is affected

Dover Fueling Solutions ProGauge MAGLINK LX Console (firmware and software) and ProGauge MAGLINK LX4 Console (firmware and software)—specific versions indicated in manufacturer references (ICSA-24-268-04)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Doverfuelingsolutions Progauge Maglink Lx4 Console

    HW
    Doverfuelingsolutions
    all versions
  • Doverfuelingsolutions Progauge Maglink Lx4 Console Firmware

    OS
    Doverfuelingsolutions
    ≤ 4.17.9e
  • Doverfuelingsolutions Progauge Maglink Lx Console

    HW
    Doverfuelingsolutions
    all versions
  • Doverfuelingsolutions Progauge Maglink Lx Console Firmware

    OS
    Doverfuelingsolutions
    ≤ 3.4.2.2.6
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2024-43692CRITICAL9.3PL ✓same product

Pominięcie uwierzytelnienia w ProGauge MAGLINK LX Console

CVE-2024-43693CRITICAL10.0PL ✓same product

Command injection w ProGauge MAGLINK LX Console — zdalne wykonanie poleceń

CVE-2024-45066CRITICAL10.0PL ✓same product

Command injection w konsolach ProGauge MAGLINK LX/LX4 — zdalne wykonanie poleceń

CVE-2024-41725HIGH8.7same product

ProGauge MAGLINK LX CONSOLE does not have sufficient filtering on input fields that are used to render pages ...

CVE-2024-45373HIGH8.7same product

Once logged in to ProGauge MAGLINK LX4 CONSOLE, a valid user can change their privileges to administrator.