Use of hard-coded credentials in Chiller SK 3232-Series and pCOWeb - CVE-2019-13553
Published: October 25, 2019
Vulnerability details
The vulnerability exists due to presence of hard-coded credentials in application code. A remote unauthenticated attacker can access the affected system using the hard-coded credentials and influence the primary operations of the affected systems, namely turning the cooling unit on and off and setting the temperature set point.
Affected software
pCOWeb