CVE-2019-19885
In Bender COMTRAXX, user authorization is validated for most, but not all, routes in the system. A user with knowledge about the routes can read and write configuration data without prior authorization. This affects COM465IP, COM465DP, COM465ID, CP700, CP907, and CP915 devices before 4.2.0.
Published:Oct 16, 2020
Last Modified:Nov 21, 2024
EPS:Oct 16, 2020
EPSS Score:0.00257
CVSS Score:9.1
Affected Products
Vendor
Product
Action
Vendor
Bender
Product
Com465dp
Bender
Com465dp
Vendor
Bender
Product
Com465dp Firmware
Bender
Com465dp Firmware
Vendor
Bender
Product
Com465id
Bender
Com465id
Vendor
Bender
Product
Com465id Firmware
Bender
Com465id Firmware
Vendor
Bender
Product
Com465ip
Bender
Com465ip
Vendor
Bender
Product
Com465ip Firmware
Bender
Com465ip Firmware
Vendor
Bender
Product
Cp700
Bender
Cp700
Vendor
Bender
Product
Cp700 Firmware
Bender
Cp700 Firmware
Vendor
Bender
Product
Cp907
Bender
Cp907
Vendor
Bender
Product
Cp907 Firmware
Bender
Cp907 Firmware
Vendor
Bender
Product
Cp915
Bender
Cp915
Vendor
Bender
Product
Cp915 Firmware
Bender
Cp915 Firmware
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
