SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-13549

The authentication mechanism on affected systems does not provide a sufficient level of protection against unauthorized configuration changes.

HIGH 7.5EPSS 1.03%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (1.03%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Rittal Chiller SK 3232-Series web interface as built upon Carel pCOWeb firmware A1.5.3 – B1.2.4. The authentication mechanism on affected systems does not provide a sufficient level of protection against unauthorized configuration changes. Primary operations, namely turning the cooling unit on and off and setting the temperature set point, can be modified without authentication.

CVSS 3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS
1.03% probability · 62th percentile
CISA KEV
Not listed
Weakness
CWE-306
Affected
carel/pcoweb firmware
Source
ics-cert@hq.dhs.gov

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.