CVE-2018-10603
31.07.2018, 17:29
Martem TELEM GW6 and GWM devices with firmware 2018.04.18-linux_4-01-601cb47 and prior do not perform authentication of IEC-104 control commands, which may allow a rogue node a remote control of the industrial process.Enginsight
Vendor | Product | Version |
---|---|---|
martem | telem-gwm_firmware | 𝑥 ≤ 2018.04.18-linux_4-01-601cb47 |
martem | telem-gw6_firmware | 𝑥 ≤ 2018.04.18-linux_4-01-601cb47 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-306 - Missing Authentication for Critical FunctionThe product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
- CWE-287 - Improper AuthenticationWhen an actor claims to have a given identity, the software does not prove or insufficiently proves that the claim is correct.