Security readout for executives and security teams
Plain-English summary
Bond JetSelect reportedly stores initial administrator passwords using a reversible XOR-based scheme. Anyone who can obtain the stored password data may be able to recover administrator passwords and take control of JetSelect configuration capabilities affecting vessel networking.
Executive priority
Prioritize where JetSelect manages live vessel networking. The business risk is loss of control over network segregation and managed device configuration, but urgency depends on local deployment and access controls.
Technical view
CVE-2019-13022 concerns ENCtool.jar and the JetSelect initial password generation algorithm. The CVE description says plaintext is XORed into the stored password value, making reversal trivial and enabling privilege escalation through recovery of JetSelect administrator passwords.
Likely exposure
Exposure appears limited to environments running Bond JetSelect, described as affecting all versions. The provided data does not identify CPEs, deployment counts, supported versions, or internet exposure patterns.
Exploitation context
The source bundle does not show KEV listing or active exploitation. Practical abuse requires access to JetSelect stored password material or related application/database data, then use of recovered administrator credentials.
Researcher notes
The provided CVE data lacks CVSS, CWE, CPEs, exploit evidence, and named fixes. Treat impact as high for confirmed deployments, but avoid broader product assumptions beyond Bond JetSelect as described.
Mitigation direction
- Check Bond or maintainer guidance for remediation; no patch is named in provided sources.
- Restrict access to JetSelect application hosts, databases, and backup files.
- Rotate JetSelect administrator passwords after remediation or compensating controls are in place.
- Review whether JetSelect remains operationally required on affected vessel networks.
- Segment management access to switches, routers, and JetSelect administration paths.
Validation and detection
- Inventory vessel and network-management systems for Bond JetSelect deployments.
- Confirm whether ENCtool.jar and the described password-generation mechanism are present.
- Identify who can access JetSelect databases, backups, and application files.
- Review JetSelect administrator accounts for unnecessary privileges or stale access.
- Check logs for unexpected JetSelect administrator configuration changes.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
Credential and access behavior lookup
The CVE wording references authentication or credential exposure, so valid-account and credential-access review may help. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.
Open ATT&CK lookupDatabase behavior lookup
The CVE wording references database injection or access, so collection and exfiltration review may help. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.
Open ATT&CK lookupCVE-2019-13022 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Unknown
- CVSS
- Not scored
- Known Exploited
- No
- Published
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS and timeline data
No CVSS vectors or timeline events were available in the normalized CVE source material.
Source materials
- CVE List V5 sourceCVE List V5
- https://labs.nettitude.com/blog/cve-2019-13021-22-23-jetselect-network-segregation-application/CVE reference · x_refsource_MISC
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
