2023-10-29 09:06:41 +00:00
{
"id" : "CVE-2023-34437" ,
"sourceIdentifier" : "ics-cert@hq.dhs.gov" ,
"published" : "2023-10-19T00:15:16.053" ,
2024-11-13 19:03:36 +00:00
"lastModified" : "2024-11-13T17:15:06.153" ,
"vulnStatus" : "Modified" ,
2024-07-14 02:06:08 +00:00
"cveTags" : [ ] ,
2023-10-29 09:06:41 +00:00
"descriptions" : [
{
"lang" : "en" ,
2024-11-13 19:03:36 +00:00
"value" : "Baker Hughes \u2013 Bently Nevada 3500 System TDI Firmware version 5.05\n\n contains\u00a0a vulnerability in their password retrieval functionality which could allow an attacker to access passwords stored on the device."
2023-10-29 09:06:41 +00:00
} ,
{
"lang" : "es" ,
"value" : "Baker Hughes en Bently Nevada 3500 System TDI Firmware versi\u00f3n 5.05 contiene una vulnerabilidad en su funcionalidad de recuperaci\u00f3n de contrase\u00f1as que podr\u00eda permitir a un atacante acceder a las contrase\u00f1as almacenadas en el dispositivo."
}
] ,
"metrics" : {
"cvssMetricV31" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" ,
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "NONE" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "HIGH" ,
"integrityImpact" : "NONE" ,
"availabilityImpact" : "NONE" ,
"baseScore" : 7.5 ,
"baseSeverity" : "HIGH"
} ,
"exploitabilityScore" : 3.9 ,
"impactScore" : 3.6
} ,
{
"source" : "ics-cert@hq.dhs.gov" ,
"type" : "Secondary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" ,
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "NONE" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "HIGH" ,
"integrityImpact" : "NONE" ,
"availabilityImpact" : "NONE" ,
"baseScore" : 7.5 ,
"baseSeverity" : "HIGH"
} ,
"exploitabilityScore" : 3.9 ,
"impactScore" : 3.6
}
]
} ,
"weaknesses" : [
{
2024-11-13 19:03:36 +00:00
"source" : "ics-cert@hq.dhs.gov" ,
2023-10-29 09:06:41 +00:00
"type" : "Primary" ,
"description" : [
{
"lang" : "en" ,
2024-11-13 19:03:36 +00:00
"value" : "CWE-732"
2023-10-29 09:06:41 +00:00
}
]
} ,
{
2024-11-13 19:03:36 +00:00
"source" : "nvd@nist.gov" ,
2023-10-29 09:06:41 +00:00
"type" : "Secondary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-200"
}
]
}
] ,
"configurations" : [
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:bakerhughes:bentley_nevada_3500_system_firmware:5.0.5:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "9329A00C-D768-442F-9CDE-0027886D9F3E"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:bakerhughes:bentley_nevada_3500_system:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "CDE17D85-8ABE-45B6-9FFB-66B74CCFF1CD"
}
]
}
]
}
] ,
"references" : [
{
"url" : "https://www.cisa.gov/news-events/ics-advisories/icsa-23-269-05" ,
"source" : "ics-cert@hq.dhs.gov" ,
"tags" : [
"Third Party Advisory" ,
"US Government Resource"
]
}
]
}