Janitza UMG Power Quality Measuring Improper Access Control (CVE-2015-3971)

high Tenable OT Security Plugin ID 501958


The remote OT asset is affected by a vulnerability.


The debug interface on Janitza UMG 508, 509, 511, 604, and 605 devices does not require authentication, which allows remote attackers to read or write to files, or execute arbitrary JASIC code, via a session on TCP port 1239.

This plugin only works with Tenable.ot.
Please visit https://www.tenable.com/products/tenable-ot for more information.


Refer to the vendor advisory.

See Also


Plugin Details

Severity: High

ID: 501958

Version: 1.1

Type: remote

Family: Tenable.ot

Published: 2/12/2024

Updated: 2/12/2024

Supported Sensors: Nessus

Risk Information


Risk Factor: Low

Score: 3.4


Risk Factor: High

Base Score: 7.5

Temporal Score: 5.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2015-3971

Vulnerability Information

CPE: cpe:/h:janitza:umg_508:-, cpe:/h:janitza:umg_509:-, cpe:/h:janitza:umg_511:-, cpe:/h:janitza:umg_604:-, cpe:/h:janitza:umg_605:-

Required KB Items: Tenable.ot/Janitza

Exploit Ease: No known exploits are available

Patch Publication Date: 10/28/2015

Vulnerability Publication Date: 10/28/2015

Reference Information

CVE: CVE-2015-3971

CWE: 284