9.1

CVE-2019-19885

In Bender COMTRAXX, user authorization is validated for most, but not all, routes in the system. A user with knowledge about the routes can read and write configuration data without prior authorization. This affects COM465IP, COM465DP, COM465ID, CP700, CP907, and CP915 devices before 4.2.0.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
BenderCom465ip Firmware Version < 4.2.0
   BenderCom465ip Version-
BenderCom465dp Firmware Version < 4.2.0
   BenderCom465dp Version-
BenderCom465id Firmware Version < 4.2.0
   BenderCom465id Version-
BenderCp700 Firmware Version < 4.2.0
   BenderCp700 Version-
BenderCp907 Firmware Version < 4.2.0
   BenderCp907 Version-
BenderCp915 Firmware Version < 4.2.0
   BenderCp915 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.26% 0.462
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.1 3.9 5.2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
nvd@nist.gov 6.4 10 4.9
AV:N/AC:L/Au:N/C:P/I:P/A:N
CWE-862 Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.