5
CVSSv2

CVE-2021-32997

Published: 25/05/2022 Updated: 14/06/2022
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The affected Baker Hughes Bentley Nevada products (3500 System 1 6.x, Part No. 3060/00 versions 6.98 and prior, 3500 System 1, Part No. 3071/xx & 3072/xx versions 21.1 HF1 and prior, 3500 Rack Configuration, Part No. 129133-01 versions 6.4 and prior, and 3500/22M Firmware, Part No. 288055-01 versions 5.05 and prior) utilize a weak encryption algorithm for storage and transmission of sensitive data, which may allow an malicious user to more easily obtain credentials used for access.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

bakerhughes bentley_nevada_3500_system_1_6.x_\\(3060\\/00\\)_firmware

bakerhughes bentley_nevada_3500_system_1_\\(3072\\/xx\\)_firmware 21.1

bakerhughes bentley_nevada_3500_system_1_\\(3072\\/xx\\)_firmware

bakerhughes bentley_nevada_3500_system_1_\\(3071\\/xx\\)_firmware 21.1

bakerhughes bentley_nevada_3500_system_1_\\(3071\\/xx\\)_firmware

bakerhughes bentley_nevada_3500\\/22m_\\(288055-01\\)_firmware

bakerhughes bentley_nevada_3500_rack_configuration_\\(129133-01\\)_firmware

ICS Advisories