CRITICAL🇵🇱 Wersja polska

CVE-2024-43692

CVSS 9.3v4.0pub. 2024-09-25upd. 2024-10-01

An attacker can directly request the ProGauge MAGLINK LX CONSOLE resource sub page with full privileges by requesting the URL directly.

🤖 AI Analysis
How it works

An attacker can bypass the authentication mechanism (CWE-288) by directly calling the URL of a protected resource in the console's web interface. The system does not properly verify whether the request comes from an authenticated user, granting full permissions access to anyone who knows or guesses the URL path. The attack is possible remotely over the network without any additional prerequisites.

Impact

An attacker gains full access to the administrative functions of the fuel system management console without the need to log in, which may enable manipulation of device configuration or reading of sensitive operational data.

Mitigation & patch

Apply patches available from the manufacturer according to the references. It is also recommended to restrict network access to the console's web interface only to trusted hosts and to isolate OT/ICS devices from public networks using a firewall.

Who is affected

Dover Fueling Solutions ProGauge MAGLINK LX Console and ProGauge MAGLINK LX4 Console devices (console firmware and software) — specific versions indicated in the manufacturer's references (CISA guide ICSA-24-268-04)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Doverfuelingsolutions Progauge Maglink Lx4 Console

    HW
    Doverfuelingsolutions
    all versions
  • Doverfuelingsolutions Progauge Maglink Lx4 Console Firmware

    OS
    Doverfuelingsolutions
    ≤ 4.17.9e
  • Doverfuelingsolutions Progauge Maglink Lx Console

    HW
    Doverfuelingsolutions
    all versions
  • Doverfuelingsolutions Progauge Maglink Lx Console Firmware

    OS
    Doverfuelingsolutions
    ≤ 3.4.2.2.6
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2024-43423CRITICAL9.3PL ✓same product

Zakodowane na stałe hasło konta administratora w ProGauge MAGLINK LX/LX4 Console

CVE-2024-43693CRITICAL10.0PL ✓same product

Command injection w ProGauge MAGLINK LX Console — zdalne wykonanie poleceń

CVE-2024-45066CRITICAL10.0PL ✓same product

Command injection w konsolach ProGauge MAGLINK LX/LX4 — zdalne wykonanie poleceń

CVE-2024-41725HIGH8.7same product

ProGauge MAGLINK LX CONSOLE does not have sufficient filtering on input fields that are used to render pages ...

CVE-2024-45373HIGH8.7same product

Once logged in to ProGauge MAGLINK LX4 CONSOLE, a valid user can change their privileges to administrator.