CVE-2019-11536: Critical severity kalkitech sync3000 vulnerability
Kalki Kalkitech SYNC3000 Substation DCU GPC v2.22.6, 2.23.0, 2.24.0, 3.0.0, 3.1.0, 3.1.16, 3.2.3, 3.2.6, 3.5.0, 3.6.0, and 3.6.1, when WebHMI is not installed, allows an attacker to inject client-side commands or scripts to be executed on the device with privileged access, aka CYB/2019/19561. The attack requires network connectivity to the device and exploits the webserver interface, typically through a browser.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-11536?
CVE-2019-11536 has been classified as a high severity vulnerability due to the potential for remote command injection.
How do I fix CVE-2019-11536?
To mitigate CVE-2019-11536, ensure that the latest firmware updates are applied to the Kalkitech SYNC3000 Substation DCU.
What versions are affected by CVE-2019-11536?
CVE-2019-11536 affects Kalkitech SYNC3000 firmware versions 2.22.6 through 3.6.1.
What kind of attack is associated with CVE-2019-11536?
CVE-2019-11536 allows attackers to inject client-side commands or scripts on affected devices.
Is WebHMI installation relevant to CVE-2019-11536?
Yes, CVE-2019-11536 occurs when the WebHMI component is not installed on the affected devices.