The Java client in Adcon Telemetry A840 Telemetry Gateway Base Station does not authenticate the station device, which allows man-in-the-middle attackers to spoof devices and obtain sensitive information by reading cleartext packet data, related to the lack of SSL support.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
https://ics-cert.us-cert.gov/advisories/ICSA-15-349-01 | third party advisory us government resource |
http://www.securityfocus.com/bid/79345 | vdb entry |