Triangle MicroWorks SCADA Data Gateway Use of Hard-coded Credentials Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of Triangle MicroWorks SCADA Data Gateway. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of certificates. The service uses a hard-coded default SSL certificate. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-20509.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: zdi

Published: 2024-05-03T01:59:22.784Z

Updated: 2024-08-02T18:10:20.663Z

Reserved: 2023-08-02T21:37:23.121Z

Link: CVE-2023-39458

cve-icon Vulnrichment

Updated: 2024-08-02T18:10:20.663Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-05-03T03:15:10.823

Modified: 2024-05-03T12:50:12.213

Link: CVE-2023-39458

cve-icon Redhat

No data.