9.3
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow more
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: disclosure@vulncheck.com (Secondary)
Description
Tattile Smart+, Vega, and Basic device families firmware versions 1.181.5 and prior ship with default credentials that are not forced to be changed during installation or commissioning. An attacker who can reach the management interface can authenticate using the default credentials and gain administrative access, enabling unauthorized access to device configuration and data.
Affected (10)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.181.5 |
| Running on/with | Platform Versions |
|---|---|
Tattile Smart+ | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.181.5 |
| Running on/with | Platform Versions |
|---|---|
Tattile Tolling+ | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.181.5 |
| Running on/with | Platform Versions |
|---|---|
Tattile Smart+ Speed | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.181.5 |
| Running on/with | Platform Versions |
|---|---|
Tattile Smart+ Traffic Light | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.181.5 |
| Running on/with | Platform Versions |
|---|---|
Tattile Axle Counter | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.181.5 |
| Running on/with | Platform Versions |
|---|---|
Tattile Vega53 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.181.5 |
| Running on/with | Platform Versions |
|---|---|
Tattile Vega33 | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.181.5 |
| Running on/with | Platform Versions |
|---|---|
Tattile Vega11 | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.181.5 |
| Running on/with | Platform Versions |
|---|---|
Tattile Basic Mk2 | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.181.5 |
| Running on/with | Platform Versions |
|---|---|
Tattile Anpr Mobile | All versions |
References (3)
Source: disclosure@vulncheck.com
Third Party AdvisoryVDB Entry
Source: disclosure@vulncheck.com
ExploitThird Party Advisory
Timeline
No history available yet.