vendor:
APOLLO VX20
by:
John Page (hyp3rlinx)
6.1
CVSS
HIGH
Incorrect Access Control (Denial of Service)
284
CWE
Product Name: APOLLO VX20
Affected Version From: APOLLO VX20 < 1.3.58
Affected Version To: 1.3.58
Patch Exists: YES
Related CWE: CVE-2024-25736
CPE: a:wyrestorm:apollo_vx20:1.3.57
Platforms Tested:
2024
WyreStorm APOLLO VX20 Incorrect Access Control DoS Vulnerability
An incorrect access control vulnerability exists in WyreStorm Apollo VX20 devices before version 1.3.58. Remote attackers can exploit this issue by sending a specific HTTP GET request to reboot the device.
Mitigation:
Update the WyreStorm Apollo VX20 device to version 1.3.58 or later to mitigate this vulnerability.