VYPR
Unrated severityNVD Advisory· Published Oct 8, 2018· Updated Sep 17, 2024

The Auto-Maskin DCU 210E, RP-210E, and Marine Pro Observer Android App transmit sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors

CVE-2018-5401

Description

The Auto-Maskin DCU 210E, RP-210E, and Marine Pro Observer Android App transmit sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors. The devices transmit process control information via unencrypted Modbus communications. Impact: An attacker can exploit this vulnerability to observe information about configurations, settings, what sensors are present and in use, and other information to aid in crafting spoofed messages. Requires access to the network. Affected releases are Auto-Maskin DCU-210E, RP-210E, and Marine Pro Observer Android App. Versions prior to 3.7 on ARMv7.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Auto-Maskin DCU-210E, RP-210E, and Marine Pro Observer App transmit process control data in cleartext over Modbus, allowing network-based sniffing of configurations and sensor information.

Vulnerability

The Auto-Maskin DCU-210E, RP-210E, and Marine Pro Observer Android App transmit process control information via unencrypted Modbus communications [1], [2]. This cleartext transmission of sensitive data (CWE-319) affects versions prior to 3.7 on ARMv7 [1]. The vulnerability allows any actor who can sniff network traffic to observe details about device configurations, settings, and sensor presence [2].

Exploitation

A remote attacker with network access to the device's Modbus communication channel can passively sniff the unencrypted traffic [1]. No authentication or user interaction is required, and the attack is remotely exploitable with low skill level [1]. The attacker simply needs to be in a position to capture network packets on the same network segment as the targeted unit [2].

Impact

Successful exploitation enables an attacker to gather intelligence about the device's configuration, settings, and which sensors are present and in use [2]. This information can be used to craft spoofed Modbus messages, potentially leading to arbitrary control of connected engine control units [2]. The required network access and passive nature of the sniffing limits direct impact, but the informational disclosure aids further attacks.

Mitigation

As of the last advisory update (CISA, February 2020), a firmware update to version 3.7 or later may address the issue, but the available references do not explicitly confirm a fix [1], [2]. Critical devices should be isolated on private, carefully secured networks and not exposed to untrusted networks [2]. If no patch is applied, network segmentation and strict access control are the primary mitigations.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

5
  • Range: <3.7
  • Range: <3.7
  • Auto-Maskin/DCU-210Ev5
    Range: 3.7
  • Auto-Maskin/Marine Pro Observer Android Appv5
    Range: 0.1
  • Auto-Maskin/RP-210Ev5
    Range: 3.7

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.