Tycon Systems TPDIN-Monitor-WEB2

Summary

CISA has identified critical vulnerabilities in Tycon Systems TPDIN-Monitor-WEB2 devices, specifically version 2.3.9. Successful exploitation could allow unauthenticated attackers to bypass login and gain administrative control, potentially disrupting critical infrastructure or causing physical damage. Tycon Systems has not provided a vendor fix, and users are advised to contact the vendor for updates.

IFF Assessment

FOE

The identified vulnerabilities allow unauthenticated attackers to gain administrative control over critical infrastructure devices, posing a significant risk to operational safety and stability.

Severity

9.8 Critical

The CVSS score of 9.8 reflects the critical severity of the vulnerabilities, which allow for authentication bypass via an alternate path and cleartext storage of sensitive information, leading to potential disruption and physical safety risks.

Defender Context

This alert highlights critical vulnerabilities in industrial control systems (ICS) that can be exploited with severe consequences. Defenders should prioritize patching or mitigating systems running the affected Tycon Systems TPDIN-Monitor-WEB2 device, especially given the lack of a vendor-provided fix. It underscores the importance of robust access controls and regular vulnerability scanning for OT environments.

Read Full Story →