The Bently Nevada 3700 series of condition monitoring...
Critical severity
Unreviewed
Published
Jul 27, 2022
to the GitHub Advisory Database
•
Updated Feb 22, 2024
Description
Published by the National Vulnerability Database
Jul 26, 2022
Published to the GitHub Advisory Database
Jul 27, 2022
Last updated
Feb 22, 2024
The Bently Nevada 3700 series of condition monitoring equipment through 2022-04-29 has a maintenance interface on port 4001/TCP with undocumented, hardcoded credentials. An attacker capable of connecting to this interface can thus trivially take over its functionality.
References