Impact
The vulnerability allows an attacker who can reach the web management interface of MOMA Seismic Station to perform actions without authenticating. An unauthenticated user can alter configuration settings, retrieve device data, or reset the device remotely, potentially disrupting monitoring operations and compromising the integrity of seismic data. The weakness is a missing authentication check, identified as CWE-306.
Affected Systems
Vendors affected are RISS SRL, product MOMA Seismic Station, specifically versions v2.4.2520 and all earlier releases.
Risk and Exploitability
The CVSS base score of 9.3 indicates critical severity, yet the EPSS score of less than 1% suggests that, at present, exploitation attempts are rare. The vulnerability is not cataloged in CISA’s KEV list. Likely attack vector is an unauthenticated network attacker accessing the web interface, which may require that the device is reachable from the attacker’s network or that the victim’s internal network is compromised. Bypassing authentication provides full control over the station’s configuration and operations, and thus poses a high risk to the availability and integrity of seismic monitoring services.
OpenCVE Enrichment