prior and BACnetstac version 4.2.1 and prior have only FTP and Telnet
available for device management. Any sensitive information communicated
through these protocols, such as credentials, is sent in cleartext. An
attacker could obtain sensitive information such as user credentials to
gain access to the system.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Sauter-controls
Subscribe
|
Bacnetstac
Subscribe
Modunet300 Ey-am300f001
Subscribe
Modunet300 Ey-am300f001 Firmware
Subscribe
Modunet300 Ey-am300f002
Subscribe
Modunet300 Ey-am300f002 Firmware
Subscribe
Nova 106 Eyk300f001
Subscribe
Nova 106 Eyk300f001 Firmware
Subscribe
Nova 220 Eyk220f001
Subscribe
Nova 220 Eyk220f001 Firmware
Subscribe
Nova 230 Eyk230f001
Subscribe
Nova 230 Eyk230f001 Firmware
Subscribe
|
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-12156 | SAUTER Controls Nova 200–220 Series with firmware version 3.3-006 and prior and BACnetstac version 4.2.1 and prior have only FTP and Telnet available for device management. Any sensitive information communicated through these protocols, such as credentials, is sent in cleartext. An attacker could obtain sensitive information such as user credentials to gain access to the system. |
Solution
No solution given by the vendor.
Workaround
SAUTER Controls has stated that this product line is no longer supported, as it was discontinued in 2016. SAUTER Controls recommends users take all necessary measures to protect the integrity of building automation network access, using all appropriate means and policies to minimize risks. Sauter Controls recommends users evaluate and upgrade legacy systems to current solutions where necessary. Affected users should contact SAUTER Controls https://www.sauter-controls.com/ for instructions on upgrading legacy systems.
| Link | Providers |
|---|---|
| https://www.cisa.gov/uscert/ics/advisories/icsa-23-012-05 |
|
Thu, 16 Jan 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2025-01-16T21:55:31.611Z
Reserved: 2023-01-04T16:24:06.705Z
Link: CVE-2023-0053
Updated: 2024-08-02T04:54:32.601Z
Status : Modified
Published: 2023-03-02T01:15:11.590
Modified: 2024-11-21T07:36:28.010
Link: CVE-2023-0053
No data.
OpenCVE Enrichment
No data.
EUVD