VendorsMartemtelem-gwm_firmwareall versions
Vulnerabilities

Martem Telem-GWM Firmware 2018.04.18-linux 4-01-601cb47

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2018-10603
Martem TELEM GW6 and GWM devices with firmware 2018.04.18-linux_4-01-601cb47 and prior do not perform authentication of IEC-104 control commands, which may allow a rogue node a remote control of the industrial process.
Published 2018-07-31 · Modified
9.8EPSS 0.034
CVE-2018-10605
Martem TELEM GW6/GWM versions prior to 2.0.87-4018403-k4 may allow unprivileged users to modify/upload a new system configuration or take the full control over the RTU using default credentials to connect to the RTU.
Published 2018-10-01 · Modified
9.0EPSS 0.015
CVE-2018-10607
Martem TELEM GW6 and GWM devices with firmware 2018.04.18-linux_4-01-601cb47 and prior allow the creation of new connections to one or more IOAs, without closing them properly, which may cause a denial of service within the industrial process control channel.
Published 2018-07-31 · Modified
7.5EPSS 0.032
CVE-2018-10609
Martem TELEM GW6 and GWM devices with firmware 2018.04.18-linux_4-01-601cb47 and prior allow improper sanitization of data over a Websocket which may allow cross-site scripting and client-side code execution with target user privileges.
Published 2018-07-31 · Modified
6.1EPSS 0.023