Vulnerabilities
Products Security index
Vulnerabilities
CVE-2023-36857
Baker Hughes Bently Nevada 3500 System Authentication Bypass by Capture-replay
CVE-2023-34437
Baker Hughes Bently Nevada 3500 System Incorrect Permission Assignment for Critical Resource
CVE-2023-34441
Baker Hughes Bently Nevada 3500 System Cleartext Transmission of Sensitive Information
CVE-2022-29953
The Bently Nevada 3700 series of condition monitoring equipment through 2022-04-29 has a maintenance interface on port 4001/TCP with undocumented, hardcoded credentials. An attacker capable of connecting to this interface can thus trivially take over its functionality.
CVE-2022-29952
Bently Nevada condition monitoring equipment through 2022-04-29 mishandles authentication. It utilizes the TDI command and data protocols (60005/TCP, 60007/TCP) for communications between the monitoring controller and System 1 and/or Bently Nevada Monitor Configuration (BNMC) software. These protocols provide configuration management and historical data related functionality. Neither protocol has any authentication features, allowing any attacker capable of communicating with the ports in question to invoke (a subset of) desired functionality.
