Baker Hughes Bently Nevada 3500 System Authentication Bypass by Capture-replay
Vulnerability Description
Baker Hughes – Bently Nevada 3500 System TDI Firmware version 5.05 contains a replay vulnerability which could allow an attacker to replay older captured packets of traffic to the device to gain access.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-36857
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Diego Zaffaroni of Nozomi Networks
Affected Vendor
Baker Hughes - Bently Nevada
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.