Show filters
22 Total Results
Displaying 1-10 of 22
Sort by:
Attacker Value
Unknown

CVE-2022-29953

Disclosure Date: July 26, 2022 (last updated February 24, 2025)
The Bently Nevada 3700 series of condition monitoring equipment through 2022-04-29 has a maintenance interface on port 4001/TCP with undocumented, hardcoded credentials. An attacker capable of connecting to this interface can thus trivially take over its functionality.
Attacker Value
Unknown

CVE-2023-36857

Disclosure Date: October 19, 2023 (last updated October 26, 2023)
Baker Hughes – Bently Nevada 3500 System TDI Firmware version 5.05 contains a replay vulnerability which could allow an attacker to replay older captured packets of traffic to the device to gain access.
Attacker Value
Unknown

CVE-2023-34441

Disclosure Date: October 19, 2023 (last updated October 26, 2023)
Baker Hughes – Bently Nevada 3500 System TDI Firmware version 5.05 contains a cleartext transmission vulnerability which could allow an attacker to steal the authentication secret from communication traffic to the device and reuse it for arbitrary requests.
Attacker Value
Unknown

CVE-2023-34437

Disclosure Date: October 19, 2023 (last updated November 13, 2024)
Baker Hughes – Bently Nevada 3500 System TDI Firmware version 5.05 contains a vulnerability in their password retrieval functionality which could allow an attacker to access passwords stored on the device.
Attacker Value
Unknown

CVE-2023-22971

Disclosure Date: January 26, 2023 (last updated February 24, 2025)
Cross Site Scripting (XSS) vulnerability in Hughes Network Systems Router Terminal for HX200 v8.3.1.14, HX90 v6.11.0.5, HX50L v6.10.0.18, HN9460 v8.2.0.48, and HN7000S v6.9.0.37, allows unauthenticated attackers to misuse frames, include JS/HTML code and steal sensitive information from legitimate users of the application.
Attacker Value
Unknown

CVE-2022-29952

Disclosure Date: July 26, 2022 (last updated February 24, 2025)
Bently Nevada condition monitoring equipment through 2022-04-29 mishandles authentication. It utilizes the TDI command and data protocols (60005/TCP, 60007/TCP) for communications between the monitoring controller and System 1 and/or Bently Nevada Monitor Configuration (BNMC) software. These protocols provide configuration management and historical data related functionality. Neither protocol has any authentication features, allowing any attacker capable of communicating with the ports in question to invoke (a subset of) desired functionality.
Attacker Value
Unknown

CVE-2021-32997

Disclosure Date: May 25, 2022 (last updated February 23, 2025)
The affected Baker Hughes Bentley Nevada products (3500 System 1 6.x, Part No. 3060/00 versions 6.98 and prior, 3500 System 1, Part No. 3071/xx & 3072/xx versions 21.1 HF1 and prior, 3500 Rack Configuration, Part No. 129133-01 versions 6.4 and prior, and 3500/22M Firmware, Part No. 288055-01 versions 5.05 and prior) utilize a weak encryption algorithm for storage and transmission of sensitive data, which may allow an attacker to more easily obtain credentials used for access.
Attacker Value
Unknown

Hughes high-performance broadband satellite modems, models HN7740S DW7000 HN700…

Disclosure Date: July 13, 2018 (last updated November 27, 2024)
Hughes high-performance broadband satellite modems, models HN7740S DW7000 HN7000S/SM, are potentially vulnerable to improper input validation. The device's advanced status web page that is linked to from the basic status web page does not appear to properly parse malformed GET requests. This may lead to a denial of service.
0
Attacker Value
Unknown

Hughes high-performance broadband satellite modems, models HN7740S DW7000 HN700…

Disclosure Date: July 13, 2018 (last updated November 27, 2024)
Hughes high-performance broadband satellite modems, models HN7740S DW7000 HN7000S/SM, uses hard coded credentials. Access to the device's default telnet port (23) can be obtained through using one of a few default credentials shared among all devices.
0
Attacker Value
Unknown

Hughes high-performance broadband satellite modems, models HN7740S DW7000 HN700…

Disclosure Date: July 13, 2018 (last updated November 27, 2024)
Hughes high-performance broadband satellite modems, models HN7740S DW7000 HN7000S/SM, lacks authentication. An unauthenticated user may send an HTTP GET request to http://[ip]/com/gatewayreset or http://[ip]/cgi/reboot.bin to cause the modem to reboot.
0