#VU71171 Missing Authentication for Critical Function in Fr. Sauter AG products - CVE-2023-0052

 

#VU71171 Missing Authentication for Critical Function in Fr. Sauter AG products - CVE-2023-0052

Published: January 16, 2023


Vulnerability identifier: #VU71171
Vulnerability risk: High
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2023-0052
CWE-ID: CWE-306
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Nova 220 (EYK220F001) DDC with BACnet connection
Nova 230 (EYK230F001) DDC with BACnet connection
Nova 106 (EYK300F001) BACnet communication card
moduNet300 (EY-AM300F001)
moduNet300 (EY-AM300F002)
Software vendor:
Fr. Sauter AG

Description

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to missing authentication for critical function within the affected software with BACnetstac version 4.2.1 and prior. A remote attacker can access the system and modify the device configuration, leading to arbitrary commands execution.


Remediation

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

External links