SAUTER Controls Nova 200–220 Series Missing Authentication for Critical Function
CVE-2023-0052

9.8CRITICAL

What is CVE-2023-0052?

The SAUTER Controls Nova 200–220 Series devices are vulnerable to unauthorized command execution due to inadequate security measures. With firmware versions 3.3-006 and earlier, as well as BACnetstac versions 4.2.1 and earlier, the devices allow remote management through Telnet and FTP protocols. An unauthorized user could exploit this vulnerability to access the device, modify settings, or execute harmful commands that jeopardize device security and integrity.

Affected Version(s)

moduNet300 (EY-AM300F001, EY-AM300F002) Firmware all versions <= 3.3-006

moduNet300 (EY-AM300F001, EY-AM300F002) BACnetstac all versions <= 4.2.1

Nova 106 (EYK300F001) BACnet communication card Firmware all versions <= 3.3-006

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jairo Alonso Ortiz, Aarón Flecha Menéndez and Iñaki Lázaro Ayanz of S21Sec
.