Use of insufficiently random values in Nucleus NET and Nucleus ReadyStart - CVE-2020-28388

 

Use of insufficiently random values in Nucleus NET and Nucleus ReadyStart - CVE-2020-28388

Published: February 10, 2021 / Updated: March 10, 2021


Vulnerability identifier: #VU50601
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-28388
CWE-ID: CWE-330
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exists due to the ISN generator relies on a combination of values that can be inferred from a network capture. A remote attacker can interfere with traffic, spoof the connection and gain access to sensitive information.


Affected software

Nucleus NET
Nucleus ReadyStart
PLUSCONTROL 1st Gen
APOGEE PXC Series (P2 Ethernet)
APOGEE PXC Series (BACnet)
TALON TC Series (BACnet)

How to mitigate CVE-2020-28388

Install updates from vendor's website.

Nucleus NET - update to 5.2
Nucleus ReadyStart - update to 2012.12
APOGEE PXC Series (P2 Ethernet) - update to 2.8.20
APOGEE PXC Series (BACnet) - update to 3.5.5
TALON TC Series (BACnet) - update to 3.5.5

External References

Related Security Bulletins