Successful exploitation of these vulnerabilities could result in an attacker accessing sensitive credentials, disrupting connected infrastructure, or manipulating physical equipment, which could present a physical safety risk.
The following versions of Tycon Systems TPDIN-Monitor-WEB2 are affected:
TPDIN-Monitor-WEB2 2.3.9
Vendor
Equipment
Tycon Systems
Tycon Systems TPDIN-Monitor-WEB2
Authentication Bypass Using an Alternate Path or Channel, Cleartext Storage of Sensitive Information
Critical Infrastructure Sectors: Critical Manufacturing
Countries/Areas Deployed: Worldwide
Company Headquarters Location: United States
The web management interface of the affected device does not perform server-side validation of credentials during the login process. By submitting empty values for both credential fields, an unauthenticated remote attacker can bypass the authentication check...
Read the full advisory on CISA →