LiveActive security incident?Get immediate response
CVE Record

CVE-2019-13022: Bond JetSelect (all versions) has an issue in the Java class (ENCtool.jar) and corresponding password gener...

Bond JetSelect (all versions) has an issue in the Java class (ENCtool.jar) and corresponding password generation algorithm (used to set initial passwords upon first installation). It XORs the plaintext into the 'encrypted' password that is then stored within the database. These steps are able to be trivially reversed, allowing for escalation of privilege within the JetSelect application through obtaining the passwords of JetSelect administrators. JetSelect administrators have the ability to modify and delete all networking configuration across a vessel, as well as altering network configuration of all managed network devices (switches, routers).

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysishigh

Security readout for executives and security teams

Plain-English summary

Bond JetSelect reportedly stores initial administrator passwords using a reversible XOR-based scheme. Anyone who can obtain the stored password data may be able to recover administrator passwords and take control of JetSelect configuration capabilities affecting vessel networking.

Executive priority

Prioritize where JetSelect manages live vessel networking. The business risk is loss of control over network segregation and managed device configuration, but urgency depends on local deployment and access controls.

Technical view

CVE-2019-13022 concerns ENCtool.jar and the JetSelect initial password generation algorithm. The CVE description says plaintext is XORed into the stored password value, making reversal trivial and enabling privilege escalation through recovery of JetSelect administrator passwords.

Likely exposure

Exposure appears limited to environments running Bond JetSelect, described as affecting all versions. The provided data does not identify CPEs, deployment counts, supported versions, or internet exposure patterns.

Exploitation context

The source bundle does not show KEV listing or active exploitation. Practical abuse requires access to JetSelect stored password material or related application/database data, then use of recovered administrator credentials.

Researcher notes

The provided CVE data lacks CVSS, CWE, CPEs, exploit evidence, and named fixes. Treat impact as high for confirmed deployments, but avoid broader product assumptions beyond Bond JetSelect as described.

Mitigation direction

  • Check Bond or maintainer guidance for remediation; no patch is named in provided sources.
  • Restrict access to JetSelect application hosts, databases, and backup files.
  • Rotate JetSelect administrator passwords after remediation or compensating controls are in place.
  • Review whether JetSelect remains operationally required on affected vessel networks.
  • Segment management access to switches, routers, and JetSelect administration paths.

Validation and detection

  • Inventory vessel and network-management systems for Bond JetSelect deployments.
  • Confirm whether ENCtool.jar and the described password-generation mechanism are present.
  • Identify who can access JetSelect databases, backups, and application files.
  • Review JetSelect administrator accounts for unnecessary privileges or stale access.
  • Check logs for unexpected JetSelect administrator configuration changes.
Prepared
Confidence
medium
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

description · low confidence lookup

Credential and access behavior lookup

The CVE wording references authentication or credential exposure, so valid-account and credential-access review may help. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.

Open ATT&CK lookup
description · low confidence lookup

Database behavior lookup

The CVE wording references database injection or access, so collection and exfiltration review may help. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2019-13022 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
2Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
n/an/an/aListed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.