SB2019030108 - Unprotected storage of credentials in Carel pCOWeb



SB2019030108 - Unprotected storage of credentials in Carel pCOWeb

Published: March 1, 2019 Updated: October 25, 2019

Security Bulletin ID SB2019030108
Severity
High
Patch available
NO
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Information disclosure

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Credentials management (CVE-ID: CVE-2019-9484)

The vulnerability allows a remote attacker to gain access to the target system.

The vulnerability exists due to improper management of credentials in the Glen Dimplex Deutschland GmbH implementation. A remote attacker can scan the ports 10000 or 10001 and obtain access via an HTTP session, as demonstrated by reading the modem password (which is 1234), or reconfiguring "party mode" or "vacation mode".

Remediation

Cybersecurity Help is not aware of any official remediation provided by the vendor.