Rittal Chiller SK 3232-Series web interface as built upon Carel pCOWeb firmware A1.5.3 – B1.2.4. The authentication mechanism on affected systems does not provide a sufficient level of protection against unauthorized configuration changes. Primary operations, namely turning the cooling unit on and off and setting the temperature set point, can be modified without authentication.
References
| Link | Resource |
|---|---|
| https://www.us-cert.gov/ics/advisories/icsa-19-297-01 | Third Party Advisory US Government Resource |
| http://seclists.org/fulldisclosure/2019/Oct/46 |
Configurations
Configuration 1 (hide)
| AND |
|
Information
Published : 2019-10-25 11:15
Updated : 2020-02-10 13:50
NVD link : CVE-2019-13549
Mitre link : CVE-2019-13549
JSON object : View
CWE
CWE-306
Missing Authentication for Critical Function
Products Affected
rittal
- chiller_sk_3232
carel
- pcoweb_firmware


