Description
The secret used for validating authentication tokens is hardcoded in device firmware for affected versions. An attacker who obtains the signing key can bypass authentication, gaining complete access to the system.
Problem types
Product status
Any version before 4.20.3
Any version before 4.20.3
Any version before 5.20.3
Credits
Pedro Umbelino of Bitsight TRACE reported these vulnerabilities to CISA.
References
www.cisa.gov/news-events/ics-advisories/icsa-25-261-07
www.doverfuelingsolutions.com/...e-maglink-lx-4-console.html