resource sub page with full privileges by requesting the URL directly.
Metrics
Affected Vendors & Products
Source | ID | Title |
---|---|---|
![]() |
EUVD-2024-40427 | An attacker can directly request the ProGauge MAGLINK LX CONSOLE resource sub page with full privileges by requesting the URL directly. |
Solution
Dover Fueling Solutions released a new software update version 4.19.10 for the MagLink LX console to address these vulnerabilities. The software release is available for installation on consoles through DFS's authorized service organizations in North America. North American users can reach DFS's customer support team by telephone at 877-679-8324.
Workaround
DFS strongly encourages users of MagLink products to: * Install MagLink consoles behind firewalls for security. * Monitor and install updates on a timely basis. * Contact DFS customer support with any questions about operations or updates of MagLink software. Alternatively, MagLink may operate offfline or disconnected from a network. Registered MagLink customers have access to technical information, updates, and technical bulletins via a DFS proprietary portal.
Tue, 01 Oct 2024 16:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Doverfuelingsolutions progauge Maglink Lx4 Console
Doverfuelingsolutions progauge Maglink Lx4 Console Firmware Doverfuelingsolutions progauge Maglink Lx Console Doverfuelingsolutions progauge Maglink Lx Console Firmware |
|
Weaknesses | NVD-CWE-Other | |
CPEs | cpe:2.3:h:doverfuelingsolutions:progauge_maglink_lx4_console:-:*:*:*:*:*:*:* cpe:2.3:h:doverfuelingsolutions:progauge_maglink_lx_console:-:*:*:*:*:*:*:* cpe:2.3:o:doverfuelingsolutions:progauge_maglink_lx4_console_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:doverfuelingsolutions:progauge_maglink_lx_console_firmware:*:*:*:*:*:*:*:* |
|
Vendors & Products |
Doverfuelingsolutions progauge Maglink Lx4 Console
Doverfuelingsolutions progauge Maglink Lx4 Console Firmware Doverfuelingsolutions progauge Maglink Lx Console Doverfuelingsolutions progauge Maglink Lx Console Firmware |
Wed, 25 Sep 2024 17:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Doverfuelingsolutions
Doverfuelingsolutions maglink Lx4 Console Doverfuelingsolutions maglink Lx Console |
|
CPEs | cpe:2.3:a:doverfuelingsolutions:maglink_lx4_console:*:*:*:*:*:*:*:* cpe:2.3:a:doverfuelingsolutions:maglink_lx_console:*:*:*:*:*:*:*:* |
|
Vendors & Products |
Doverfuelingsolutions
Doverfuelingsolutions maglink Lx4 Console Doverfuelingsolutions maglink Lx Console |
|
Metrics |
ssvc
|
Wed, 25 Sep 2024 00:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An attacker can directly request the ProGauge MAGLINK LX CONSOLE resource sub page with full privileges by requesting the URL directly. | |
Title | Dover Fueling Solutions ProGauge MAGLINK LX CONSOLE Authentication Bypass Using an Alternate Path or Channel | |
Weaknesses | CWE-288 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2024-09-25T17:00:19.138Z
Reserved: 2024-09-05T20:11:00.318Z
Link: CVE-2024-43692

Updated: 2024-09-25T17:00:12.826Z

Status : Analyzed
Published: 2024-09-25T01:15:43.110
Modified: 2024-10-01T16:22:38.197
Link: CVE-2024-43692

No data.

No data.