← back
CVE-2019-13549

CVE-2019-13549

EPSS 1.0%CWE-306
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS EPSS 1.0%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
25 Oct 2019Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Rittal Chiller SK 3232-Series web interface as built upon Carel pCOWeb firmware A1.5.3 – B1.2.4. The authentication mechanism on affected systems does not provide a sufficient level of protection against unauthorized configuration changes. Primary operations, namely turning the cooling unit on and off and setting the temperature set point, can be modified without authentication.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →