5
CVSSv2

CVE-2019-13549

Published: 25/10/2019 Updated: 10/02/2020
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

Rittal Chiller SK 3232-Series web interface as built upon Carel pCOWeb firmware A1.5.3 – B1.2.4. The authentication mechanism on affected systems does not provide a sufficient level of protection against unauthorized configuration changes. Primary operations, namely turning the cooling unit on and off and setting the temperature set point, can be modified without authentication.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

carel pcoweb_firmware

Exploits

The Carel pCOWeb card exposes a Modbus interface to the network By design, Modbus does not provide authentication, allowing to control the affected system Version A 1411 - B 142 is affected ...