CVE-2026-12183
9.3
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L
Summary
Nefteprodukttekhnika BUK TS-G Gas Station Automation System 2.9.1 through 2.10.2 on Linux contains an Improper Authentication vulnerability (CWE-287) in the system configuration module.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Nefteprodukttekhnika LLC | BUK TS-G Gas Station Automation System | 2.9.1 <= 2.10.2 | affected |
Weaknesses
- CWE-287: CWE-287 Improper Authentication
- CWE-306: CWE-306 Missing Authentication for Critical Function
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: yes
- Technical Impact: total
References
- https://github.com/ciprobe/bukts_auth_bypass
- https://bukts.ru/repo-bukts-current
- https://cwe.mitre.org/data/definitions/287.html
- https://cwe.mitre.org/data/definitions/306.html
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.