An Unrestricted Upload issue was discovered in Marel Food Processing Systems M3000 terminal associated with the following systems: A320, A325, A371, A520 Master, A520 Slave, A530, A542, A571, Check Bin Grader, FlowlineQC T376, IPM3 Dual Cam v132, IPM3 Dual Cam v139, IPM3 Single Cam v132, P520, P574, SensorX13 QC flow line, SensorX23 QC Master, SensorX23 QC Slave, Speed Batcher, T374, T377, V36, V36B, and V36C; M3210 terminal associated with the same systems as the M3000 terminal identified above; M3000 desktop software associated with the same systems as the M3000 terminal identified above; MAC4 controller associated with the same systems as the M3000 terminal identified above; SensorX23 X-ray machine; SensorX25 X-ray machine; and MWS2 weighing system. This vulnerability allows an attacker to modify the operation and upload firmware changes without detection.

Project Subscriptions

Vendors Products
A320 Firmware Subscribe
A325 Firmware Subscribe
A371 Firmware Subscribe
A520 Master Subscribe
A520 Master Firmware Subscribe
A520 Slave Subscribe
A520 Slave Firmware Subscribe
A530 Firmware Subscribe
A542 Firmware Subscribe
A571 Firmware Subscribe
Check Bin Grader Subscribe
Check Bin Grader Firmware Subscribe
Flowlineqc T376 Subscribe
Flowlineqc T376 Firmware Subscribe
Ipm3 Dual Cam Subscribe
Ipm3 Dual Cam Firmware Subscribe
P520 Firmware Subscribe
P574 Firmware Subscribe
Sensorx13 Qc Flow Line Subscribe
Sensorx13 Qc Flow Line Firmware Subscribe
Sensorx23 Qc Master Subscribe
Sensorx23 Qc Master Firmware Subscribe
Sensorx23 Qc Slave Subscribe
Sensorx23 Qc Slave Firmware Subscribe
Speed Batcher Subscribe
Speed Batcher Firmware Subscribe
T374 Firmware Subscribe
T377 Firmware Subscribe
V36 Firmware Subscribe
V36b Firmware Subscribe
V36c Firmware Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2017-15109 An Unrestricted Upload issue was discovered in Marel Food Processing Systems M3000 terminal associated with the following systems: A320, A325, A371, A520 Master, A520 Slave, A530, A542, A571, Check Bin Grader, FlowlineQC T376, IPM3 Dual Cam v132, IPM3 Dual Cam v139, IPM3 Single Cam v132, P520, P574, SensorX13 QC flow line, SensorX23 QC Master, SensorX23 QC Slave, Speed Batcher, T374, T377, V36, V36B, and V36C; M3210 terminal associated with the same systems as the M3000 terminal identified above; M3000 desktop software associated with the same systems as the M3000 terminal identified above; MAC4 controller associated with the same systems as the M3000 terminal identified above; SensorX23 X-ray machine; SensorX25 X-ray machine; and MWS2 weighing system. This vulnerability allows an attacker to modify the operation and upload firmware changes without detection.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2024-08-05T15:18:49.755Z

Reserved: 2017-02-16T00:00:00.000Z

Link: CVE-2017-6041

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2017-06-30T03:29:00.563

Modified: 2025-04-20T01:37:25.860

Link: CVE-2017-6041

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses