ZeroHour

CVE-2019-19885

CVSS 3.1
9.1 critical
EPSS
<1%p61
Published
()
Modified
Description

In Bender COMTRAXX, user authorization is validated for most, but not all, routes in the system. A user with knowledge about the routes can read and write configuration data without prior authorization. This affects COM465IP, COM465DP, COM465ID, CP700, CP907, and CP915 devices before 4.2.0.

Vendors
bender
Products
com465ip firmware, com465dp firmware, com465id firmware, cp700 firmware, cp907 firmware, cp915 firmware
Weakness
CWE-862
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.