CVE-2018-19023

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
25/01/2019
Last modified:
09/10/2019

Description

Hetronic Nova-M prior to verson r161 uses fixed codes that are reproducible by sniffing and re-transmission. This can lead to unauthorized replay of a command, spoofing of an arbitrary message, or keeping the controlled load in a permanent "stop" state.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:hetronic:nova-m_firmware:*:*:*:*:*:*:*:* r161 (excluding)
cpe:2.3:h:hetronic:nova-m:-:*:*:*:*:*:*:*
cpe:2.3:o:hetronic:es-can-hl_firmware:*:*:*:*:*:*:*:* main_r1864 (excluding)
cpe:2.3:h:hetronic:es-can-hl:-:*:*:*:*:*:*:*
cpe:2.3:o:hetronic:bms-hl_firmware:*:*:*:*:*:*:*:* main_r1175 (excluding)
cpe:2.3:h:hetronic:bms-hl:-:*:*:*:*:*:*:*
cpe:2.3:o:hetronic:mlc_firmware:*:*:*:*:*:*:*:* main_r1600 (excluding)
cpe:2.3:h:hetronic:mlc:-:*:*:*:*:*:*:*
cpe:2.3:o:hetronic:dc_mobile_firmware:*:*:*:*:*:*:*:* main_r515 (excluding)
cpe:2.3:h:hetronic:dc_mobile:-:*:*:*:*:*:*:*