Attacker Value
Unknown
(1 user assessed)
Exploitability
Unknown
(1 user assessed)
User Interaction
Unknown
Privileges Required
Unknown
Attack Vector
Unknown
1

CVE-2022-29953

Add MITRE ATT&CK tactics and techniques that apply to this CVE.

Description

The Bently Nevada 3700 series of condition monitoring equipment through 2022-04-29 has a maintenance interface on port 4001/TCP with undocumented, hardcoded credentials. An attacker capable of connecting to this interface can thus trivially take over its functionality.

Add Assessment

1
Technical Analysis

RCE vulnerability that effects Bently Nevada 3701 (OT device)
Maintenance interface has undocumented,
hardcoded credentials

Source: https://www.forescout.com/resources/ot-icefall-report/

General Information

Additional Info

Technical Analysis