CVE-2018-10605
01.10.2018, 16:29
Martem TELEM GW6/GWM versions prior to 2.0.87-4018403-k4 may allow unprivileged users to modify/upload a new system configuration or take the full control over the RTU using default credentials to connect to the RTU.Enginsight
Vendor | Product | Version |
---|---|---|
martem | telem-gw6_firmware | 𝑥 < 2.0.87-4018403-k4 |
martem | telem-gwm_firmware | 𝑥 < 2.0.87-4018403-k4 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-276 - Incorrect Default PermissionsDuring installation, installed file permissions are set to allow anyone to modify those files.
- CWE-1188 - Insecure Default Initialization of ResourceThe software initializes or sets a resource with a default that is intended to be changed by the administrator, but the default is not secure.