Baker Hughes – Bently Nevada 3500 System TDI Firmware version 5.05

contains a vulnerability in their password retrieval functionality which could allow an attacker to access passwords stored on the device.
Advisories
Source ID Title
EUVD EUVD EUVD-2023-38513 Baker Hughes – Bently Nevada 3500 System TDI Firmware version 5.05 contains a vulnerability in their password retrieval functionality which could allow an attacker to access passwords stored on the device.
Fixes

Solution

No solution given by the vendor.


Workaround

Baker Hughes – Bently Nevada recommends that users follow their hardening guidelines to reduce the risk of exploitation. Customers who have registered for access to Baker Hughes DAM may directly access the hardening guideline at https://dam.bakerhughes.com/media/?mediaId=32F7FC2F-9F22-4C69-BB847565B7834D08 .For customers that do not have access to Baker Hughes DAM may send an email to bentlysupport@bakerhughes.com to request document 106M9733.

History

Thu, 16 Jan 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 13 Nov 2024 17:15:00 +0000

Type Values Removed Values Added
Description Baker Hughes – Bently Nevada 3500 System TDI Firmware version 5.05 contains a vulnerability in their password retrieval functionality which could allow an attacker to access passwords stored on the device. Baker Hughes – Bently Nevada 3500 System TDI Firmware version 5.05 contains a vulnerability in their password retrieval functionality which could allow an attacker to access passwords stored on the device.
Title Baker Hughes Bently Nevada 3500 System Exposure of Sensitive Information to an Unauthorized Actor Baker Hughes Bently Nevada 3500 System Incorrect Permission Assignment for Critical Resource
Weaknesses CWE-732

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2025-01-16T21:29:21.547Z

Reserved: 2023-07-21T16:52:22.731Z

Link: CVE-2023-34437

cve-icon Vulnrichment

Updated: 2024-08-02T16:10:07.079Z

cve-icon NVD

Status : Modified

Published: 2023-10-19T00:15:16.053

Modified: 2024-11-21T08:07:14.437

Link: CVE-2023-34437

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.