vendor:
Positron Broadcast Signal Processor TRA7005
by:
LiquidWorm
6.1
CVSS
HIGH
Authentication Bypass
287
CWE
Product Name: Positron Broadcast Signal Processor TRA7005
Affected Version From: 1.2
Affected Version To: TRA7K5_REV102
Patch Exists: NO
Related CWE: Not specified
CPE: h:positron:positron_broadcast_signal_processor_tra7005:1.20
Platforms Tested:
Not specified
Positron Broadcast Signal Processor TRA7005 v1.20 – Authentication Bypass
The Positron Broadcast Digital Signal Processor TRA7005 is vulnerable to an authentication bypass that allows attackers to gain unauthorized access to protected areas of the application by manipulating the password management functionality. By exploiting this vulnerability, attackers can bypass Digest authentication, set a user's password to any value, or even remove it completely.
Mitigation:
To mitigate this vulnerability, it is recommended to update the affected device to a patched version provided by the vendor. Additionally, users should ensure strong password policies are in place and monitor for any unauthorized access attempts.