CVE-2022-29952
Summary
| CVE | CVE-2022-29952 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-07-26 22:15:00 UTC |
| Updated | 2022-08-02 20:53:00 UTC |
| Description | Bently Nevada condition monitoring equipment through 2022-04-29 mishandles authentication. It utilizes the TDI command and data protocols (60005/TCP, 60007/TCP) for communications between the monitoring controller and System 1 and/or Bently Nevada Monitor Configuration (BNMC) software. These protocols provide configuration management and historical data related functionality. Neither protocol has any authentication features, allowing any attacker capable of communicating with the ports in question to invoke (a subset of) desired functionality. |
Risk And Classification
Problem Types: CWE-306
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Bakerhughes | Bently Nevada 3701/40 | - | All | All | All |
| Operating System | Bakerhughes | Bently Nevada 3701/40 Firmware | All | All | All | All |
| Hardware | Bakerhughes | Bently Nevada 3701/44 | - | All | All | All |
| Operating System | Bakerhughes | Bently Nevada 3701/44 Firmware | All | All | All | All |
| Hardware | Bakerhughes | Bently Nevada 3701/46 | - | All | All | All |
| Operating System | Bakerhughes | Bently Nevada 3701/46 Firmware | All | All | All | All |
| Hardware | Bakerhughes | Bently Nevada 60m100 | - | All | All | All |
| Operating System | Bakerhughes | Bently Nevada 60m100 Firmware | - | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Bently Nevada ADAPT 3701/4X Series and 60M100 | CISA | MISC | www.cisa.gov | |
| Blog - Forescout | MISC | www.forescout.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.