The embedded web server lacks authentication and access controls, allowing unrestricted remote access. This could lead to configuration changes, operational disruption, or arbitrary code execution depending on the environment and exposed functionality.
Metrics
Affected Vendors & Products
References
History
Thu, 22 May 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 21 May 2025 20:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The embedded web server lacks authentication and access controls, allowing unrestricted remote access. This could lead to configuration changes, operational disruption, or arbitrary code execution depending on the environment and exposed functionality. | |
Title | AutomationDirect MB-Gateway Missing Authentication for Critical Function | |
Weaknesses | CWE-306 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: icscert
Published: 2025-05-21T19:52:13.068Z
Updated: 2025-05-22T18:49:49.738Z
Reserved: 2025-05-14T16:57:44.359Z
Link: CVE-2025-36535

Updated: 2025-05-22T18:48:57.063Z

Status : Awaiting Analysis
Published: 2025-05-21T20:15:31.533
Modified: 2025-05-21T20:24:58.133
Link: CVE-2025-36535

No data.