CVE-2019-6527: Critical severity kunbus pr100088 modbus gateway firmware vulnerability
PR100088 Modbus gateway versions prior to Release R02 (or Software Version 1.1.13166) may allow an attacker to be able to change the password for an admin user who is currently or previously logged in, provided the device has not been restarted.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-6527?
CVE-2019-6527 is a vulnerability in Kunbus PR100088 Modbus gateway versions prior to Release R02 (or Software Version 1.1.13166) that allows an attacker to change the password for an admin user who is currently or previously logged in, without the device being restarted.
How severe is CVE-2019-6527?
CVE-2019-6527 has a severity rating of 9.8 out of 10, which is considered critical.
What is the affected software of CVE-2019-6527?
The affected software is Kunbus PR100088 Modbus gateway firmware versions prior to Release R02 (or Software Version 1.1.13166).
Can an attacker change the password for an admin user without restarting the device?
Yes, an attacker can change the password for an admin user on Kunbus PR100088 Modbus gateway versions prior to Release R02 (or Software Version 1.1.13166) without the device being restarted.
Where can I find more information about CVE-2019-6527?
You can find more information about CVE-2019-6527 at the following reference link: https://ics-cert.us-cert.gov/advisories/ICSA-19-036-05