CVE detail
CVE-2019-19885 — CVE-2019-19885
Published 2020-10-16 · Modified 2026-06-17 · Vendor bender · Product com465ip_firmware · Source nvd
CRITICAL
severity
CVSS-derived band
0.0100
EPSS probability
exploitation probability, 30d
60.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
In Bender COMTRAXX, user authorization is validated for most, but not all, routes in the system. A user with knowledge about the routes can read and write configuration data without prior authorization. This affects COM465IP, COM465DP, COM465ID, CP700, CP907, and CP915 devices before 4.2.0.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References