Sensitive Data Exposure in Kunbus Modbus Gateway by Kunbus
CVE-2019-6531

8.1HIGH

Key Information:

Vendor

Kunbus

Vendor
CVE Published:
2 April 2019

What is CVE-2019-6531?

The Kunbus PR100088 Modbus gateway prior to Release R02 is susceptible to a vulnerability that allows an attacker positioned in a man-in-the-middle (MITM) scenario to capture sensitive data, including passwords, through an unprotected HTTP GET request. This can lead to unauthorized access and exploitation of the system, highlighting the urgent need for secure data transmission mechanisms.

Affected Version(s)

PR100088 Modbus gateway All versions prior to Release R02 (or Software Version 1.1.13166)

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.