Weak password requirements issue exists in CHOCO TEI WATCHER mini (IB-MCT001) all versions. If this issue is exploited, a brute-force attack may allow an attacker unauthorized access and login.
The vulnerability results from the lack of appropriate requirements regarding password complexity or length (CWE-521 — Weak Password Requirements). An attacker can conduct a brute-force attack, systematically trying successive password combinations until gaining access. Due to the network attack vector (AV:N) and lack of authentication requirements (PR:N) and user interaction (UI:N), the attack is possible remotely and without any prerequisites.
An attacker can gain unauthorized access to the device and log in, which in an ICS/OT class device can lead to unauthorized viewing or manipulation of production line data, and potentially also disrupt its operation.
Apply patches available from the manufacturer according to references. Additionally, it is recommended to isolate the device from the public network, use strong, unique passwords, and restrict network access to the device using a firewall or OT network segmentation.
CHOCO TEI WATCHER mini (IB-MCT001) — all software versions
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H