CVE-2022-29953

Severity CVSS v4.0:
Pending analysis
Type:
CWE-798 Use of Hard-coded Credentials
Publication date:
26/07/2022
Last modified:
13/02/2024

Description

The Bently Nevada 3700 series of condition monitoring equipment through 2022-04-29 has a maintenance interface on port 4001/TCP with undocumented, hardcoded credentials. An attacker capable of connecting to this interface can thus trivially take over its functionality.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:bakerhughes:bently_nevada_3701\/40_firmware:*:*:*:*:*:*:*:* 4.1 (excluding)
cpe:2.3:h:bakerhughes:bently_nevada_3701\/40:-:*:*:*:*:*:*:*
cpe:2.3:o:bakerhughes:bently_nevada_3701\/44_firmware:*:*:*:*:*:*:*:* 4.1 (excluding)
cpe:2.3:h:bakerhughes:bently_nevada_3701\/44:-:*:*:*:*:*:*:*
cpe:2.3:o:bakerhughes:bently_nevada_3701\/46_firmware:*:*:*:*:*:*:*:* 4.1 (excluding)
cpe:2.3:h:bakerhughes:bently_nevada_3701\/46:-:*:*:*:*:*:*:*
cpe:2.3:o:bakerhughes:bently_nevada_60m100_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:bakerhughes:bently_nevada_60m100:-:*:*:*:*:*:*:*