VYPR
Unrated severityNVD Advisory· Published Oct 18, 2023· Updated Jan 16, 2025

Baker Hughes Bently Nevada 3500 System Incorrect Permission Assignment for Critical Resource

CVE-2023-34437

Description

Baker Hughes – Bently Nevada 3500 System TDI Firmware version 5.05

contains a vulnerability in their password retrieval functionality which could allow an attacker to access passwords stored on the device.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Incorrect permission assignment in Bently Nevada 3500 TDI Firmware 5.05 password retrieval allows remote attackers to access stored passwords.

Vulnerability

CVE-2023-34437 is an incorrect permission assignment for critical resource vulnerability (CWE-732) in the password retrieval functionality of Baker Hughes Bently Nevada 3500 System TDI Firmware version 5.05 [1]. The affected product is the Bently Nevada 3500 Rack running TDI Firmware version 5.05. The flaw allows an attacker to access passwords stored on the device due to improper permission checks on the password retrieval mechanism.

Exploitation

An attacker can exploit this vulnerability remotely over the network with low attack complexity [1]. No authentication or user interaction is required. The attacker sends crafted requests to the password retrieval functionality of the device, bypassing permission checks to obtain stored passwords.

Impact

Successful exploitation results in the disclosure of stored passwords, leading to a high confidentiality impact [1]. Integrity and availability are not affected. The attacker gains access to sensitive credentials, which could be used for further unauthorized access to the device or network.

Mitigation

As of the advisory publication date (2023-10-18), no fix has been released for CVE-2023-34437 [1]. The vendor has not provided workarounds or mitigations. The vulnerability is not listed on the CISA Known Exploited Vulnerabilities (KEV) catalog. Users should monitor vendor advisories for future updates.

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.