Missing Authentication for Critical Function in Bently Nevada products - CVE-2022-29952
Published: July 8, 2022
Vulnerability details
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to the affected product uses protocols to provide configuration management and historical data related functionality without any authentication features. A remote attacker can read or write files on the controllers or cause a denial of service (DoS) condition.
Affected software
Bently Nevada 3701/40
Bently Nevada 3701/44
Bently Nevada 3701/46
How to mitigate CVE-2022-29952
Bently Nevada 3701/44 - update to 4.1
Bently Nevada 3701/46 - update to 4.1