CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
NONE
AV:N/AC:L/Au:N/C:P/I:P/A:N
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
AI Score
Confidence
High
EPSS
Percentile
57.8%
In Bender COMTRAXX, user authorization is validated for most, but not all, routes in the system. A user with knowledge about the routes can read and write configuration data without prior authorization. This affects COM465IP, COM465DP, COM465ID, CP700, CP907, and CP915 devices before 4.2.0.
Vendor | Product | Version | CPE |
---|---|---|---|
bender | com465ip_firmware | * | cpe:2.3:o:bender:com465ip_firmware:*:*:*:*:*:*:*:* |
bender | com465ip | - | cpe:2.3:h:bender:com465ip:-:*:*:*:*:*:*:* |
bender | com465dp_firmware | * | cpe:2.3:o:bender:com465dp_firmware:*:*:*:*:*:*:*:* |
bender | com465dp | - | cpe:2.3:h:bender:com465dp:-:*:*:*:*:*:*:* |
bender | com465id_firmware | * | cpe:2.3:o:bender:com465id_firmware:*:*:*:*:*:*:*:* |
bender | com465id | - | cpe:2.3:h:bender:com465id:-:*:*:*:*:*:*:* |
bender | cp700_firmware | * | cpe:2.3:o:bender:cp700_firmware:*:*:*:*:*:*:*:* |
bender | cp700 | - | cpe:2.3:h:bender:cp700:-:*:*:*:*:*:*:* |
bender | cp907_firmware | * | cpe:2.3:o:bender:cp907_firmware:*:*:*:*:*:*:*:* |
bender | cp907 | - | cpe:2.3:h:bender:cp907:-:*:*:*:*:*:*:* |
CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
NONE
AV:N/AC:L/Au:N/C:P/I:P/A:N
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
AI Score
Confidence
High
EPSS
Percentile
57.8%