The password recovery mechanism for the forgotten password in Riello Netman 204 allows an attacker to reset the admin password and take over control of the device.This issue affects Netman 204: through 4.05.
The vulnerability (CWE-640) results from improper implementation of the password recovery mechanism. An attacker can use the password reset procedure in such a way as to set a new administrator password without the need to verify identity. Network access to the device's network is the only necessary condition to carry out the attack — no prior credentials or user interaction are required.
The attacker gains full administrative control over the Riello Netman 204 device, which enables changing its configuration, disrupting UPS operation, and potentially cutting off power to critical infrastructure.
Apply patches available from the manufacturer according to the references provided. Until updates are applied, it is recommended to isolate Netman 204 devices from public networks and restrict access to the management interface exclusively to trusted hosts through firewall or network segmentation.
Riello Netman 204 (firmware) in all versions up to and including 4.05.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XRiello Ups Netman 204
HWRiello-Upsall versionsRiello Ups Netman 204 Firmware
OSRiello-Ups≤ 4.05
Related vulnerabilities
RCE w Riello-Ups NetMan 204 — upload webshella przez firmware
Riello NetMan 204 — command injection i bypass uwierzytelnienia
All versions of NetMan 204 allow an attacker that knows the MAC and serial number of the device to reset the a...
There is a CSRF vulnerability on Netman-204 version 02.05. An attacker could manage to change administrator pa...
Improper neutralization of special elements results in a SQL Injection vulnerability in Riello Netman 204. It ...