PR100088 Modbus gateway versions prior to Release R02 (or Software Version 1.1.13166) may allow an attacker to be able to change the password for an admin user who is currently or previously logged in, provided the device has not been restarted.
References
Link | Resource |
---|---|
https://ics-cert.us-cert.gov/advisories/ICSA-19-036-05 | Mitigation Third Party Advisory US Government Resource |
Configurations
Configuration 1 (hide)
AND |
|
Information
Published : 2019-02-12 09:29
Updated : 2023-01-31 13:00
NVD link : CVE-2019-6527
Mitre link : CVE-2019-6527
JSON object : View
CWE
CWE-287
Improper Authentication
Products Affected
kunbus
- pr100088_modbus_gateway_firmware
- pr100088_modbus_gateway