CVE-2023-0053 affects SAUTER Controls Nova 200–220 Series devices with specific firmware and BACnetstac versions, where device management relies solely on cleartext FTP and Telnet protocols. This critical vulnerability, rated 7.5 HIGH, allows an unauthenticated remote attacker to intercept sensitive information, including user credentials, due to the lack of encryption. While no active exploits or public exploit code are currently known, and community discussion is minimal, the potential for unauthorized system access remains significant.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 3.3-006CPE matchmatch criteria | cpe:2.3:o:sauter-controls:nova_220_eyk220f001_firmware:*:*:*:*:*:*:*:* | ||
<= 3.3-006CPE matchmatch criteria | cpe:2.3:o:sauter-controls:nova_230_eyk230f001_firmware:*:*:*:*:*:*:*:* | ||
<= 3.3-006CPE matchmatch criteria | cpe:2.3:o:sauter-controls:nova_106_eyk300f001_firmware:*:*:*:*:*:*:*:* | ||
<= 3.3-006CPE matchmatch criteria | cpe:2.3:o:sauter-controls:modunet300_ey-am300f001_firmware:*:*:*:*:*:*:*:* | ||
<= 3.3-006CPE matchmatch criteria | cpe:2.3:o:sauter-controls:modunet300_ey-am300f002_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.