Description
Bently Nevada condition monitoring equipment through 2022-04-29 mishandles authentication. It utilizes the TDI command and data protocols (60005/TCP, 60007/TCP) for communications between the monitoring controller and System 1 and/or Bently Nevada Monitor Configuration (BNMC) software. These protocols provide configuration management and historical data related functionality. Neither protocol has any authentication features, allowing any attacker capable of communicating with the ports in question to invoke (a subset of) desired functionality.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
No history.
Subscriptions
Bakerhughes
Subscribe
Bently Nevada 3701\/40
Subscribe
Bently Nevada 3701\/40 Firmware
Subscribe
Bently Nevada 3701\/44
Subscribe
Bently Nevada 3701\/44 Firmware
Subscribe
Bently Nevada 3701\/46
Subscribe
Bently Nevada 3701\/46 Firmware
Subscribe
Bently Nevada 60m100
Subscribe
Bently Nevada 60m100 Firmware
Subscribe
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-03T06:33:43.189Z
Reserved: 2022-04-29T00:00:00.000Z
Link: CVE-2022-29952
No data.
Status : Modified
Published: 2022-07-26T22:15:10.843
Modified: 2024-11-21T07:00:03.173
Link: CVE-2022-29952
No data.
OpenCVE Enrichment
No data.
Weaknesses