vendor:
Optergy BMS
by:
LiquidWorm
9.8
CVSS
CRITICAL
Remote Code Execution
78
CWE
Product Name: Optergy BMS
Affected Version From: <=2.3.0a
Affected Version To: <=2.0.3a
Patch Exists: YES
Related CWE: CVE-2019-7276
CPE: 2.3:a:optergy:optergy_bms:2.3.0a
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: None
2019
Optergy 2.3.0a – Remote Code Execution
Unauthenticated Remote Root Exploit in Optergy BMS (Console Backdoor) Affected version <=2.0.3a (Proton and Enterprise)
Mitigation:
Upgrade to the latest version of Optergy BMS