The Carlson VASCO-B GNSS Receiver lacks an authentication mechanism,
allowing an attacker with network access to directly access and modify
its configuration and operational functions without needing credentials.
allowing an attacker with network access to directly access and modify
its configuration and operational functions without needing credentials.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
Carlson Software recommends users update to Version 1.4.0 or greater. For more information contact Carlson Software https://www.carlsonsw.com/support-and-training/
Workaround
No workaround given by the vendor.
References
History
Tue, 28 Apr 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Carlson VASCO-B GNSS Receiver lacks an authentication mechanism, allowing an attacker with network access to directly access and modify its configuration and operational functions without needing credentials. | |
| Title | Carlson Software VASCO-B GNSS Receiver Missing Authentication for Critical Function | |
| Weaknesses | CWE-306 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2026-04-28T17:34:56.130Z
Reserved: 2026-03-10T16:52:36.791Z
Link: CVE-2026-3893
No data.
Status : Awaiting Analysis
Published: 2026-04-28T19:37:39.647
Modified: 2026-04-28T20:10:23.367
Link: CVE-2026-3893
No data.
OpenCVE Enrichment
No data.
Weaknesses