CVE-2018-5401: The Auto-Maskin DCU 210E, RP-210E, and Marine Pro Observer Android App transmit sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors
The Auto-Maskin DCU 210E, RP-210E, and Marine Pro Observer Android App transmit sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors. The devices transmit process control information via unencrypted Modbus communications. Impact: An attacker can exploit this vulnerability to observe information about configurations, settings, what sensors are present and in use, and other information to aid in crafting spoofed messages. Requires access to the network. Affected releases are Auto-Maskin DCU-210E, RP-210E, and Marine Pro Observer Android App. Versions prior to 3.7 on ARMv7.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2018-5401?
CVE-2018-5401 is classified as a medium severity vulnerability due to the transmission of sensitive data in cleartext.
How do I fix CVE-2018-5401?
To mitigate CVE-2018-5401, ensure all devices use encrypted communication channels instead of unencrypted Modbus.
What devices are affected by CVE-2018-5401?
The Auto-Maskin DCU 210E, RP-210E, and Marine Pro Observer Android App are affected by CVE-2018-5401.
What type of data is exposed in CVE-2018-5401?
CVE-2018-5401 exposes sensitive or security-critical data during the unencrypted transmission.
Can unauthorized actors exploit CVE-2018-5401?
Yes, unauthorized actors can sniff the communication channel and access sensitive information due to CVE-2018-5401.