First published: Mon Mar 23 2020(Updated: )
In Auto-Maskin RP210E Versions 3.7 and prior, DCU210E Versions 3.7 and prior and Marine Observer Pro (Android App), the software contains a mechanism for users to recover or change their passwords without knowing the original password, but the mechanism is weak.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Auto-Maskin RP-210E firmware | <=3.7 | |
Auto-Maskin RP 210E firmware | ||
Auto-Maskin DCU-210E firmware | <=3.7 | |
Auto-Maskin DCU-210E firmware | ||
Auto-Maskin Marine Pro Observer |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-6560 has been classified with a medium severity level due to its potential to allow unauthorized password recovery.
To fix CVE-2019-6560, upgrade to versions later than 3.7 of the Auto-Maskin RP210E firmware or DCU210E firmware.
CVE-2019-6560 affects Auto-Maskin RP210E firmware and DCU210E firmware versions up to and including 3.7, as well as the Marine Observer Pro Android App.
Yes, CVE-2019-6560 can be exploited remotely due to the weak password recovery mechanism.
If using an affected version related to CVE-2019-6560, it is recommended to update the software immediately to mitigate the vulnerability.