VYPR
Unrated severityNVD Advisory· Published May 22, 2019· Updated Aug 4, 2024

CVE-2019-11536

CVE-2019-11536

Description

Kalkitech SYNC3000 substation DCU GPC vulnerable to client-side script injection via webserver when WebHMI not installed.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Kalkitech SYNC3000 substation DCU GPC vulnerable to client-side script injection via webserver when WebHMI not installed.

Vulnerability

Kalkitech SYNC3000 Substation DCU GPC versions 2.22.6, 2.23.0, 2.24.0, 3.0.0, 3.1.0, 3.1.16, 3.2.3, 3.2.6, 3.5.0, 3.6.0, and 3.6.1, when WebHMI is not installed, contain a vulnerability that allows an attacker to inject client-side commands or scripts to be executed on the device with privileged access. The flaw resides in the webserver interface and does not require authentication.

Exploitation

An attacker with network connectivity to the device can exploit the webserver interface, typically through a browser, by sending crafted requests that inject client-side commands or scripts. No authentication is required, and the attack can be performed remotely over the network.

Impact

Successful exploitation allows the attacker to execute arbitrary client-side commands or scripts on the device with privileged access. This could lead to unauthorized information disclosure, modification of device settings, or further compromise of the substation network.

Mitigation

As of the publication date, no official patch or mitigation has been disclosed in the available references [1]. Users are advised to monitor vendor security advisories and consider network segmentation or firewall rules to restrict access to the affected devices until a fix is released.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • Kalki Kalkitech/SYNC3000 Substation DCU GPCdescription
  • Range: 2.22.6, 2.23.0, 2.24.0, 3.0.0, 3.1.0, 3.1.16, 3.2.3, 3.2.6, 3.5.0, 3.6.0, 3.6.1

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

2

News mentions

0

No linked articles in our index yet.