SB2018102420 - Authentication bypass in Telecrane F25 Series
Published: October 24, 2018
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Authentication bypass (CVE-ID: CVE-2018-17935)
The vulnerability allows an adjacent attacker to bypass authentication on the target system.
The vulnerability exists due to use of fixed codes that are reproducible by sniffing and re-transmission. A remote unauthenticated attacker can bypass authentication to replay commands, spoof arbitrary message, or keep the controlled load in a permanent “stop” state.
Remediation
Install update from vendor's website.