← Back to home
ICSA-19-141-01  ·  Published 2019-05-21  ·  View on CISA ICS-CERT ↗

Computrols CBAS Web

CVSS 8.8 HIGH

Risk Summary

Successful exploitation of these vulnerabilities could allow unauthorized actions with administrative privileges, disclosure of sensitive information, execution of code within a user 's browser, execution of unauthorized OS commands, unauthorized access to the database, execution of unauthorized SQL commands, authentication bypass, or decryption of passwords.

Remediations

  • Computrols recommends users upgrade to the following versions or later for each respective major versions of CBAS Web: 19.0.1
  • Computrols recommends users upgrade to the following versions or later for each respective major versions of CBAS Web: 18.0.1
  • Computrols recommends users upgrade to the following versions or later for each respective major versions of CBAS Web: 15.0.1
  • Computrols recommends users upgrade to the following versions or later for each respective major versions of CBAS Web: 14.0.1
  • Computrols recommends users upgrade to the following versions or later for each respective major versions of CBAS Web: 8.0.7
  • Computrols recommends users upgrade to the following versions or later for each respective major versions of CBAS Web: 7.2.1-Beta
  • Computrols recommends users upgrade to the following versions or later for each respective major versions of CBAS Web: 6.9.2
  • Computrols recommends users upgrade to the following versions or later for each respective major versions of CBAS Web: 4.8.2
  • Computrols recommends users upgrade to the following versions or later for each respective major versions of CBAS Web: 3.15.1
  • Updated software can be obtained by contacting Computrols Technical Support

Affected Vendors

Computrols

Affected Products (1)

Computrols · CBAS Web a Web Building Management System (BMS) < 19.0.1 | < 18.0.1 | < 15.0.1 | < 14.0.1 | < 8.0.7 | < 7.2.1-Beta | < 6.9.2 | < 4.8.2 | < 3.15.1

Affected Sectors

Commercial Facilities, Government Facilities, Healthcare and Public Health

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more