Incorrect validation vulnerability of the data entered, allowing an attacker with access to the network on which the affected device is located to use the discovery port protocol (1925/UDP) to obtain device-specific information without the need for authentication.

Fixes

Solution

The information published in this port is public and non-confidential. Its purpose is to make devices discoverable through software tools such as Ingeteam PAC Factory. If there is a cybersecurity concern about the data displayed, the port can be disabled on each device through its internal firewall service.


Workaround

No workaround given by the vendor.

History

Fri, 20 Sep 2024 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2024-09-20T14:54:20.421Z

Reserved: 2023-07-19T11:41:50.175Z

Link: CVE-2023-3770

cve-icon Vulnrichment

Updated: 2024-08-02T07:08:50.119Z

cve-icon NVD

Status : Modified

Published: 2023-10-02T14:15:10.090

Modified: 2024-11-21T08:18:01.537

Link: CVE-2023-3770

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.