{"api_version":"1","generated_at":"2026-07-23T13:25:43+00:00","cve":"CVE-2023-34441","urls":{"html":"https://cve.report/CVE-2023-34441","api":"https://cve.report/api/cve/CVE-2023-34441.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2023-34441","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2023-34441"},"summary":{"title":"CVE-2023-34441","description":"Baker Hughes – Bently Nevada 3500 System TDI Firmware version 5.05\n\n contains a cleartext transmission vulnerability which could allow an attacker to \n\nsteal the authentication secret from communication traffic to the device and reuse it for arbitrary requests.","state":"PUBLIC","assigner":"ics-cert@hq.dhs.gov","published_at":"2023-10-19 00:15:00","updated_at":"2023-10-25 14:14:00"},"problem_types":["CWE-319"],"metrics":[],"references":[{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-23-269-05","name":"https://www.cisa.gov/news-events/ics-advisories/icsa-23-269-05","refsource":"MISC","tags":[],"title":"Baker Hughes Bently Nevada 3500 | CISA","mime":"text/html","httpstatus":"200","archivestatus":"429"},{"url":"https://www.cve.org/CVERecord?id=CVE-2023-34441","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2023-34441","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2023","cve_id":"34441","vulnerable":"-1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"bakerhughes","cpe5":"bentley_nevada_3500_system","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2023","cve_id":"34441","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"bakerhughes","cpe5":"bentley_nevada_3500_system_firmware","cpe6":"5.0.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_version":"4.0","data_type":"CVE","data_format":"MITRE","CVE_data_meta":{"ID":"CVE-2023-34441","ASSIGNER":"ics-cert@hq.dhs.gov","STATE":"PUBLIC"},"description":{"description_data":[{"lang":"eng","value":"\n\n\nBaker Hughes – Bently Nevada 3500 System TDI Firmware version 5.05\n\n contains a cleartext transmission vulnerability which could allow an attacker to \n\nsteal the authentication secret from communication traffic to the device and reuse it for arbitrary requests.\n\n"}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-319 Cleartext Transmission of Sensitive Information","cweId":"CWE-319"}]}]},"affects":{"vendor":{"vendor_data":[{"vendor_name":"Baker Hughes - Bently Nevada","product":{"product_data":[{"product_name":"Bently Nevada 3500 System","version":{"version_data":[{"version_affected":"=","version_value":"5.05"}]}}]}}]}},"references":{"reference_data":[{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-23-269-05","refsource":"MISC","name":"https://www.cisa.gov/news-events/ics-advisories/icsa-23-269-05"}]},"generator":{"engine":"Vulnogram 0.1.0-dev"},"source":{"advisory":"ICSA-23-269-05","discovery":"EXTERNAL"},"work_around":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"\n\n\n\n\n\n\n\n\nBaker Hughes – Bently Nevada recommends that users follow their \nhardening guidelines to reduce the risk of exploitation. Customers who \nhave registered for access to Baker Hughes DAM may directly access the \nhardening guideline at <a target=\"_blank\" rel=\"nofollow\" href=\"https://dam.bakerhughes.com/media/?mediaId=32F7FC2F-9F22-4C69-BB847565B7834D08\">https://dam.bakerhughes.com/media/?mediaId=32F7FC2F-9F22-4C69-BB847565B7834D08</a><span style=\"background-color: var(--wht);\">.</span><p>For customers that do not have access to Baker Hughes DAM may send an email to <a target=\"_blank\" rel=\"nofollow\">bentlysupport@bakerhughes.com</a><span style=\"background-color: var(--wht);\">&nbsp;to request document 106M9733.</span></p>"}],"value":"\n\n\n\n\n\n\n\nBaker Hughes – Bently Nevada recommends that users follow their \nhardening guidelines to reduce the risk of exploitation. Customers who \nhave registered for access to Baker Hughes DAM may directly access the \nhardening guideline at  https://dam.bakerhughes.com/media/?mediaId=32F7FC2F-9F22-4C69-BB847565B7834D08 https://dam.bakerhughes.com/media/ .For customers that do not have access to Baker Hughes DAM may send an email to bentlysupport@bakerhughes.com to request document 106M9733.\n\n"}],"credits":[{"lang":"en","value":"Diego Zaffaroni of Nozomi Networks"}],"impact":{"cvss":[{"attackComplexity":"LOW","attackVector":"ADJACENT_NETWORK","availabilityImpact":"LOW","baseScore":6.8,"baseSeverity":"MEDIUM","confidentialityImpact":"HIGH","integrityImpact":"LOW","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L","version":"3.1"}]}},"nvd":{"publishedDate":"2023-10-19 00:15:00","lastModifiedDate":"2023-10-25 14:14:00","problem_types":["CWE-319"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":8.2,"baseSeverity":"HIGH"},"exploitabilityScore":3.9,"impactScore":4.2}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"AND","children":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:bakerhughes:bentley_nevada_3500_system_firmware:5.0.5:*:*:*:*:*:*:*","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":false,"cpe23Uri":"cpe:2.3:h:bakerhughes:bentley_nevada_3500_system:-:*:*:*:*:*:*:*","cpe_name":[]}]}],"cpe_match":[]}]}},"legacy_mitre":{"record":null,"notes":[]}}}