Missing Authentication for Critical Function in Fr. Sauter AG products - CVE-2023-0052
Published: January 16, 2023
Vulnerability details
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to missing authentication for critical function within the affected software with BACnetstac version 4.2.1 and prior. A remote attacker can access the system and modify the device configuration, leading to arbitrary commands execution.
Affected software
Nova 230 (EYK230F001) DDC with BACnet connection
Nova 106 (EYK300F001) BACnet communication card
moduNet300 (EY-AM300F001)
moduNet300 (EY-AM300F002)