SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-19885

In Bender COMTRAXX, user authorization is validated for most, but not all, routes in the system.

CRITICAL 9.1EPSS 1.00%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (1.00%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

In Bender COMTRAXX, user authorization is validated for most, but not all, routes in the system. A user with knowledge about the routes can read and write configuration data without prior authorization. This affects COM465IP, COM465DP, COM465ID, CP700, CP907, and CP915 devices before 4.2.0.

CVSS 3.1
9.1 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
EPSS
1.00% probability · 61th percentile
CISA KEV
Not listed
Weakness
CWE-862
Affected
bender/com465ip firmware · bender/com465dp firmware · bender/com465id firmware · bender/cp700 firmware · bender/cp907 firmware · bender/cp915 firmware
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.