{"document":{"acknowledgments":[{"organization":"CERT@VDE","summary":"coordination","urls":["https://certvde.com"]},{"organization":"Maxim Rupp","summary":"reporting"}],"category":"csaf_security_advisory","csaf_version":"2.0","distribution":{"tlp":{"label":"WHITE","url":"https://www.first.org/tlp/"}},"lang":"en-GB","notes":[{"category":"summary","text":"Bender is publishing this advisory to inform customers about a security vulnerability in all devices running the COMTRAXX software.\n\nThe user authorization is validated for most, but not all routes in the system. A user with knowledge about the routes can read and write configuration data without prior authorization.","title":"Summary"},{"category":"description","text":"The vulnerability allows a malicious entity to bypass credential check.","title":"Impact"},{"category":"description","text":"• restrict network access to the above-mentioned devices\n\n• install latest software update","title":"Mitigation"},{"category":"description","text":"Please install V4.2.0. (https://www.bender.de/service-support/downloadbereich)","title":"Remediation"}],"publisher":{"category":"vendor","contact_details":"psirt@bender.de","name":"Bender GmbH & Co. KG","namespace":"https://www.bender.de"},"references":[{"category":"external","summary":"CERT@VDE Security Advisories for Bender GmbH & Co. KG","url":"https://certvde.com/en/advisories/vendor/bender"},{"category":"self","summary":"VDE-2020-043: Bender: COMTRAXX < 4.2.0 affected by inadquate credentials check vulnerability - HTML","url":"https://certvde.com/en/advisories/VDE-2020-043"},{"category":"self","summary":"VDE-2020-043: Bender: COMTRAXX < 4.2.0 affected by inadquate credentials check vulnerability - CSAF","url":"https://bender.csaf-tp.certvde.com/.well-known/csaf/white/2020/vde-2020-043.json"}],"title":"Bender: COMTRAXX < 4.2.0 affected by inadquate credentials check vulnerability","tracking":{"aliases":["VDE-2020-043"],"current_release_date":"2020-10-16T06:54:00.000Z","generator":{"date":"2025-03-24T11:31:57.923Z","engine":{"name":"Secvisogram","version":"2.5.21"}},"id":"VDE-2020-043","initial_release_date":"2020-10-16T06:54:00.000Z","revision_history":[{"date":"2020-10-16T06:54:00.000Z","number":"1","summary":"Initial revision."}],"status":"final","version":"1"}},"product_tree":{"branches":[{"branches":[{"branches":[{"category":"product_name","name":"COM465DP","product":{"name":"COM465DP","product_id":"CSAFPID-11001","product_identification_helper":{"model_numbers":["95061060","95061061"]}}},{"category":"product_name","name":"COM465ID","product":{"name":"COM465ID","product_id":"CSAFPID-11002","product_identification_helper":{"model_numbers":["95061070"]}}},{"category":"product_name","name":"COM465IP","product":{"name":"COM465IP","product_id":"CSAFPID-11003","product_identification_helper":{"model_numbers":["95061065","95061066"]}}},{"category":"product_name","name":"CP700","product":{"name":"CP700","product_id":"CSAFPID-11004","product_identification_helper":{"model_numbers":["95061030"]}}},{"category":"product_name","name":"CP907","product":{"name":"CP907","product_id":"CSAFPID-11005","product_identification_helper":{"model_numbers":["95061080"]}}},{"category":"product_name","name":"CP915","product":{"name":"CP915","product_id":"CSAFPID-11006","product_identification_helper":{"model_numbers":["95061081","95061085","95061092"]}}}],"category":"product_family","name":"Hardware"},{"branches":[{"category":"product_version_range","name":"<4.2.0","product":{"name":"Firmware <4.2.0","product_id":"CSAFPID-21001"}},{"category":"product_version","name":"4.2.0","product":{"name":"Firmware 4.2.0","product_id":"CSAFPID-22001"}}],"category":"product_family","name":"Firmware"}],"category":"vendor","name":"Bender"}],"product_groups":[{"group_id":"CSAFGID-0001","product_ids":["CSAFPID-31001","CSAFPID-31002","CSAFPID-31003","CSAFPID-31004","CSAFPID-31005","CSAFPID-31006"],"summary":"Affected Products."},{"group_id":"CSAFGID-0002","product_ids":["CSAFPID-32001","CSAFPID-32002","CSAFPID-32003","CSAFPID-32004","CSAFPID-32005","CSAFPID-32006"],"summary":"Fixed Products."}],"relationships":[{"category":"installed_on","full_product_name":{"name":"Firmware 4.2.0 installed on CP915","product_id":"CSAFPID-32001"},"product_reference":"CSAFPID-22001","relates_to_product_reference":"CSAFPID-11006"},{"category":"installed_on","full_product_name":{"name":"Firmware 4.2.0 installed on COM465ID","product_id":"CSAFPID-32002"},"product_reference":"CSAFPID-22001","relates_to_product_reference":"CSAFPID-11002"},{"category":"installed_on","full_product_name":{"name":"Firmware 4.2.0 installed on COM465IP","product_id":"CSAFPID-32003"},"product_reference":"CSAFPID-22001","relates_to_product_reference":"CSAFPID-11003"},{"category":"installed_on","full_product_name":{"name":"Firmware 4.2.0 installed on CP700","product_id":"CSAFPID-32004"},"product_reference":"CSAFPID-22001","relates_to_product_reference":"CSAFPID-11004"},{"category":"installed_on","full_product_name":{"name":"Firmware 4.2.0 installed on CP907","product_id":"CSAFPID-32005"},"product_reference":"CSAFPID-22001","relates_to_product_reference":"CSAFPID-11005"},{"category":"installed_on","full_product_name":{"name":"Firmware 4.2.0 installed on CP915","product_id":"CSAFPID-32006"},"product_reference":"CSAFPID-22001","relates_to_product_reference":"CSAFPID-11006"},{"category":"installed_on","full_product_name":{"name":"Firmware <4.2.0 installed on CP915","product_id":"CSAFPID-31001"},"product_reference":"CSAFPID-21001","relates_to_product_reference":"CSAFPID-11006"},{"category":"installed_on","full_product_name":{"name":"Firmware <4.2.0 installed on COM465ID","product_id":"CSAFPID-31002"},"product_reference":"CSAFPID-21001","relates_to_product_reference":"CSAFPID-11002"},{"category":"installed_on","full_product_name":{"name":"Firmware <4.2.0 installed on COM465IP","product_id":"CSAFPID-31003"},"product_reference":"CSAFPID-21001","relates_to_product_reference":"CSAFPID-11003"},{"category":"installed_on","full_product_name":{"name":"Firmware <4.2.0 installed on CP700","product_id":"CSAFPID-31004"},"product_reference":"CSAFPID-21001","relates_to_product_reference":"CSAFPID-11004"},{"category":"installed_on","full_product_name":{"name":"Firmware <4.2.0 installed on CP907","product_id":"CSAFPID-31005"},"product_reference":"CSAFPID-21001","relates_to_product_reference":"CSAFPID-11005"},{"category":"installed_on","full_product_name":{"name":"Firmware <4.2.0 installed on CP915","product_id":"CSAFPID-31006"},"product_reference":"CSAFPID-21001","relates_to_product_reference":"CSAFPID-11006"}]},"vulnerabilities":[{"cve":"CVE-2019-19885","cwe":{"id":"CWE-862","name":"Missing Authorization"},"notes":[{"audience":"all","category":"description","text":"In Bender COMTRAXX, user authorization is validated for most, but not all, routes in the system. A user with knowledge about the routes can read and write configuration data without prior authorization. This affects COM465IP, COM465DP, COM465ID, CP700, CP907, and CP915 devices before 4.2.0.","title":"Vulnerability Description"}],"product_status":{"fixed":["CSAFPID-32001","CSAFPID-32002","CSAFPID-32003","CSAFPID-32004","CSAFPID-32005","CSAFPID-32006"],"known_affected":["CSAFPID-31001","CSAFPID-31002","CSAFPID-31003","CSAFPID-31004","CSAFPID-31005","CSAFPID-31006"]},"remediations":[{"category":"mitigation","details":"• restrict network access to the above-mentioned devices\n\n• install latest software update","group_ids":["CSAFGID-0001"]},{"category":"vendor_fix","details":"Please install V4.2.0. (https://www.bender.de/service-support/downloadbereich)","group_ids":["CSAFGID-0001"]}],"scores":[{"cvss_v3":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":9.1,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","environmentalScore":9.1,"environmentalSeverity":"CRITICAL","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","temporalScore":9.1,"temporalSeverity":"CRITICAL","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","version":"3.1"},"products":["CSAFPID-31001","CSAFPID-31002","CSAFPID-31003","CSAFPID-31004","CSAFPID-31005","CSAFPID-31006"]}],"title":"CVE-2019-19885"}]}