Baker Hughes Bently Nevada 3701/40 Firmware

CPE Details

Baker Hughes Bently Nevada 3701/40 Firmware
-
2022-08-02
14h15 +00:00
2022-08-02
14h35 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:o:bakerhughes:bently_nevada_3701\/40_firmware:-:*:*:*:*:*:*:*

Informations

Vendor

bakerhughes

Product

bently_nevada_3701\/40_firmware

Version

-

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2022-29953 2022-07-26 19h42 +00:00 The Bently Nevada 3700 series of condition monitoring equipment through 2022-04-29 has a maintenance interface on port 4001/TCP with undocumented, hardcoded credentials. An attacker capable of connecting to this interface can thus trivially take over its functionality.
9.8
Critical
CVE-2022-29952 2022-07-26 19h42 +00:00 Bently Nevada condition monitoring equipment through 2022-04-29 mishandles authentication. It utilizes the TDI command and data protocols (60005/TCP, 60007/TCP) for communications between the monitoring controller and System 1 and/or Bently Nevada Monitor Configuration (BNMC) software. These protocols provide configuration management and historical data related functionality. Neither protocol has any authentication features, allowing any attacker capable of communicating with the ports in question to invoke (a subset of) desired functionality.
9.1
Critical