There is no limit to the number of attempts to authenticate for the local configuration pages for the Hills ComNav Version 3002-19 interface, which allows local attackers to brute-force credentials.
                
            Metrics
Affected Vendors & Products
Advisories
    | Source | ID | Title | 
|---|---|---|
  EUVD | 
                EUVD-2022-31077 | There is no limit to the number of attempts to authenticate for the local configuration pages for the Hills ComNav Version 3002-19 interface, which allows local attackers to brute-force credentials. | 
Fixes
    Solution
Carrier recommends users upgrade to Version 4000-12 or later, which is the latest supported version at the time of this publication. Please contact the Hills distributor to acquire the firmware update. More information on this issue can be found in Carrier product security advisory number CARR-PSA-002-1121.
Workaround
No workaround given by the vendor.
References
        History
                    No history.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2025-04-16T16:28:15.650Z
Reserved: 2022-03-21T00:00:00.000Z
Link: CVE-2022-26519
No data.
Status : Modified
Published: 2022-04-20T16:15:08.603
Modified: 2024-11-21T06:54:06.343
Link: CVE-2022-26519
No data.
                        OpenCVE Enrichment
                    No data.
 EUVD