contains a vulnerability in their password retrieval functionality which could allow an attacker to access passwords stored on the device.
Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-38513 | Baker Hughes – Bently Nevada 3500 System TDI Firmware version 5.05 contains a vulnerability in their password retrieval functionality which could allow an attacker to access passwords stored on the device. |
Solution
No solution given by the vendor.
Workaround
Baker Hughes – Bently Nevada recommends that users follow their hardening guidelines to reduce the risk of exploitation. Customers who have registered for access to Baker Hughes DAM may directly access the hardening guideline at https://dam.bakerhughes.com/media/?mediaId=32F7FC2F-9F22-4C69-BB847565B7834D08 .For customers that do not have access to Baker Hughes DAM may send an email to bentlysupport@bakerhughes.com to request document 106M9733.
Thu, 16 Jan 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 13 Nov 2024 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Baker Hughes – Bently Nevada 3500 System TDI Firmware version 5.05 contains a vulnerability in their password retrieval functionality which could allow an attacker to access passwords stored on the device. | Baker Hughes – Bently Nevada 3500 System TDI Firmware version 5.05 contains a vulnerability in their password retrieval functionality which could allow an attacker to access passwords stored on the device. |
| Title | Baker Hughes Bently Nevada 3500 System Exposure of Sensitive Information to an Unauthorized Actor | Baker Hughes Bently Nevada 3500 System Incorrect Permission Assignment for Critical Resource |
| Weaknesses | CWE-732 |
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2025-01-16T21:29:21.547Z
Reserved: 2023-07-21T16:52:22.731Z
Link: CVE-2023-34437
Updated: 2024-08-02T16:10:07.079Z
Status : Modified
Published: 2023-10-19T00:15:16.053
Modified: 2024-11-21T08:07:14.437
Link: CVE-2023-34437
No data.
OpenCVE Enrichment
No data.
EUVD