SB2016100701 - Unauthorized access to GE Bently Nevada 3500/22M



SB2016100701 - Unauthorized access to GE Bently Nevada 3500/22M

Published: October 7, 2016

Security Bulletin ID SB2016100701
Severity
High
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Improper authorization (CVE-ID: CVE-2016-5788)

The vulnerability allows a remote unauthenticated user to obtain elevated privileges.

The vulnerability exists due to presence of several open ports on the device, which allow unauthenticated attacker to gain privileged access. A remote attacker can connect to the device and perform certain actions as legitimate user.

Successful exploitation of this vulnerability results in malicious user's unauthorized access to the affected device with elevated privileges.


Remediation

Install update from vendor's website.