In Auto-Maskin RP210E Versions 3.7 and prior, DCU210E Versions 3.7 and prior and Marine Observer Pro (Android App), the software contains a mechanism for users to recover or change their passwords without knowing the original password, but the mechanism is weak.
References
Link | Resource |
---|---|
https://www.us-cert.gov/ics/advisories/icsa-20-051-04 | Third Party Advisory US Government Resource |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
|
Information
Published : 2020-03-23 13:15
Updated : 2020-03-25 09:32
NVD link : CVE-2019-6560
Mitre link : CVE-2019-6560
JSON object : View
CWE
CWE-640
Weak Password Recovery Mechanism for Forgotten Password
Products Affected
auto-maskin
- dcu_210_firmware
- dcu_210
- marine_pro_observer
- rp210e
- rp210e_firmware