VYPR
Vendor

Bakerhughes

Products
10
CVEs
6
Across products
16
Status
Private

Products

10

Recent CVEs

6
  • CVE-2022-29953CriJul 26, 2022
    risk 0.64cvss 9.8epss 0.01

    The Bently Nevada 3700 series of condition monitoring equipment through 2022-04-29 has a maintenance interface on port 4001/TCP with undocumented, hardcoded credentials. An attacker capable of connecting to this interface can thus trivially take over its functionality.

  • CVE-2022-29952CriJul 26, 2022
    risk 0.59cvss 9.1epss 0.01

    Bently Nevada condition monitoring equipment through 2022-04-29 mishandles authentication. It utilizes the TDI command and data protocols (60005/TCP, 60007/TCP) for communications between the monitoring controller and System 1 and/or Bently Nevada Monitor Configuration (BNMC)…

  • CVE-2021-32997HigMay 25, 2022
    risk 0.53cvss 8.2epss 0.00

    The affected Baker Hughes Bentley Nevada products (3500 System 1 6.x, Part No. 3060/00 versions 6.98 and prior, 3500 System 1, Part No. 3071/xx & 3072/xx versions 21.1 HF1 and prior, 3500 Rack Configuration, Part No. 129133-01 versions 6.4 and prior, and 3500/22M Firmware, Part…

  • CVE-2023-34437HigOct 19, 2023
    risk 0.49cvss 7.5epss 0.00

    Baker Hughes – Bently Nevada 3500 System TDI Firmware version 5.05 contains a vulnerability in their password retrieval functionality which could allow an attacker to access passwords stored on the device.

  • CVE-2023-34441MedOct 19, 2023
    risk 0.44cvss 6.8epss 0.00

    Baker Hughes – Bently Nevada 3500 System TDI Firmware version 5.05 contains a cleartext transmission vulnerability which could allow an attacker to steal the authentication secret from communication traffic to the device and reuse it for arbitrary requests.

  • CVE-2023-36857MedOct 19, 2023
    risk 0.35cvss 5.4epss 0.00

    Baker Hughes – Bently Nevada 3500 System TDI Firmware version 5.05 contains a replay vulnerability which could allow an attacker to replay older captured packets of traffic to the device to gain access.