CISA

Tycon Systems TPDIN-Monitor-WEB2

From Cybersecurity and Infrastructure Security Agency ↗

Successful exploitation of these vulnerabilities could result in an attacker accessing sensitive credentials, disrupting connected infrastructure, or manipulating physical equipment, which could present a physical safety risk.

The following versions of Tycon Systems TPDIN-Monitor-WEB2 are affected:

TPDIN-Monitor-WEB2 2.3.9 

Vendor

Equipment

Tycon Systems

Tycon Systems TPDIN-Monitor-WEB2

Authentication Bypass Using an Alternate Path or Channel, Cleartext Storage of Sensitive Information

Critical Infrastructure Sectors: Critical Manufacturing

Countries/Areas Deployed: Worldwide

Company Headquarters Location: United States

The web management interface of the affected device does not perform server-side validation of credentials during the login process. By submitting empty values for both credential fields, an unauthenticated remote attacker can bypass the authentication check...