SB2019030108 - Unprotected storage of credentials in Carel pCOWeb
Published: March 1, 2019 Updated: October 25, 2019
Security Bulletin ID
SB2019030108
Severity
High
Patch available
NO
Number of vulnerabilities
1
Exploitation vector
Remote access
Highest impact
Information disclosure
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Credentials management (CVE-ID: CVE-2019-9484)
The vulnerability allows a remote attacker to gain access to the target system.
The vulnerability exists due to improper management of credentials in the Glen Dimplex Deutschland GmbH implementation. A remote attacker can scan the ports 10000 or 10001 and obtain access via an HTTP session, as demonstrated by reading the modem password (which is 1234), or reconfiguring "party mode" or "vacation mode".
Remediation
Cybersecurity Help is not aware of any official remediation provided by the vendor.