CVE-2018-19023
8.8
Vector
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD
Description
Hetronic Nova-M prior to verson r161 uses fixed codes that are reproducible by sniffing and re-transmission. This can lead to unauthorized replay of a command, spoofing of an arbitrary message, or keeping the controlled load in a permanent "stop" state.
Affected (5)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before r161 |
| Running on/with | Platform Versions |
|---|---|
Hetronic Nova M | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before main_r1864 |
| Running on/with | Platform Versions |
|---|---|
Hetronic Es Can Hl | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before main_r1175 |
| Running on/with | Platform Versions |
|---|---|
Hetronic Bms Hl | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before main_r1600 |
| Running on/with | Platform Versions |
|---|---|
Hetronic Mlc | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before main_r515 |
| Running on/with | Platform Versions |
|---|---|
Hetronic Dc Mobile | All versions |
Related CWEs
CWE-287
Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
CWE-294
Authentication Bypass by Capture-replay
A capture-replay flaw exists when the design of the product makes it possible for a malicious user to sniff network traffic and bypass authentication by replaying it to the server in question to the same effect as the original message (or with minor changes).
References (4)
Source: ics-cert@hq.dhs.gov
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Timeline
No history available yet.