#VU71171 Missing Authentication for Critical Function in Fr. Sauter AG products - CVE-2023-0052
Published: January 16, 2023
Nova 220 (EYK220F001) DDC with BACnet connection
Nova 230 (EYK230F001) DDC with BACnet connection
Nova 106 (EYK300F001) BACnet communication card
moduNet300 (EY-AM300F001)
moduNet300 (EY-AM300F002)
Fr. Sauter AG
Description
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to missing authentication for critical function within the affected software with BACnetstac version 4.2.1 and prior. A remote attacker can access the system and modify the device configuration, leading to arbitrary commands execution.