In Bender COMTRAXX, user authorization is validated for most, but not all, routes in the system. A user with knowledge about the routes can read and write configuration data without prior authorization. This affects COM465IP, COM465DP, COM465ID, CP700, CP907, and CP915 devices before 4.2.0.
References
Link Resource
https://cert.vde.com/en-us/advisories/vde-2020-043 Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2020-10-16T12:55:30

Updated: 2020-10-16T12:55:30

Reserved: 2019-12-18T00:00:00


Link: CVE-2019-19885

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2020-10-16T13:15:11.627

Modified: 2020-10-26T20:33:33.783


Link: CVE-2019-19885

JSON object: View

cve-icon Redhat Information

No data.

CWE