CVE Vulnerabilities

CVE-2023-34441

Cleartext Transmission of Sensitive Information

Published: Oct 19, 2023 | Modified: Nov 21, 2024
CVSS 3.x
8.2
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Baker Hughes – Bently Nevada 3500 System TDI Firmware version 5.05

contains a cleartext transmission vulnerability which could allow an attacker to

steal the authentication secret from communication traffic to the device and reuse it for arbitrary requests.

Weakness

The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

Affected Software

Name Vendor Start Version End Version
Bentley_nevada_3500_system_firmware Bakerhughes 5.0.5 (including) 5.0.5 (including)

Potential Mitigations

References