vendor:
Osprey Pump Controller
by:
LiquidWorm
7.5
CVSS
HIGH
Backdoor Access
CWE
Product Name: Osprey Pump Controller
Affected Version From: Software Build ID 20211018, Production 10/18/2021
Affected Version To: Mirage App: MirageAppManager, Release [1.0.1]
Patch Exists: No
Related CWE:
CPE: a:propump_and_controls:osprey_pump_controller:1.0.1
Platforms Tested:
2021
Osprey Pump Controller 1.0.1 – Administrator Backdoor Access
ProPump and Controls, Inc.’s Osprey Pump Controller 1.0.1 is vulnerable to a backdoor access vulnerability. This vulnerability allows an attacker to gain access to the system without authentication. The system does not have any password protection unless requested by the customer. This vulnerability can be exploited by an attacker to gain access to the system and modify the settings.
Mitigation:
ProPump and Controls, Inc. should implement password protection for the system and ensure that the system is not accessible without authentication.