Rittal Chiller SK 3232-Series web interface as built upon Carel pCOWeb firmware A1.5.3 – B1.2.4. The authentication mechanism on affected systems does not provide a sufficient level of protection against unauthorized configuration changes. Primary operations, namely turning the cooling unit on and off and setting the temperature set point, can be modified without authentication.
References
| Link | Resource |
|---|---|
| http://seclists.org/fulldisclosure/2019/Oct/46 | |
| https://www.us-cert.gov/ics/advisories/icsa-19-297-01 | Third Party Advisory US Government Resource |
| http://seclists.org/fulldisclosure/2019/Oct/46 | |
| https://www.us-cert.gov/ics/advisories/icsa-19-297-01 | Third Party Advisory US Government Resource |
Configurations
Configuration 1 (hide)
| AND |
|
History
No history.
Information
Published : 2019-10-25 18:15
Updated : 2024-11-21 04:25
NVD link : CVE-2019-13549
Mitre link : CVE-2019-13549
CVE.ORG link : CVE-2019-13549
JSON object : View
Products Affected
carel
- pcoweb_firmware
rittal
- chiller_sk_3232
CWE
CWE-306
Missing Authentication for Critical Function
