vendor:
Cleber Broadcast Multi-Purpose Platform
by:
Gjoko 'LiquidWorm' Krstic
6.1
CVSS
HIGH
Unauthenticated Device Configuration and Client-Side Hidden Functionality Disclosure
284
CWE
Product Name: Cleber Broadcast Multi-Purpose Platform
Affected Version From: 1.0.0 Revision 7304
Affected Version To: XS2DAB v1.50 rev 6267
Patch Exists: NO
Related CWE:
CPE: a:elber_srl:cleber_broadcast_multi-purpose_platform:1.0.0
Platforms Tested: NBFM Controller, embOS/IP
2023
Elber Cleber/3 Broadcast Multi-Purpose Platform 1.0.0 Device Configuration Vulnerability
The Elber Cleber/3 Broadcast Multi-Purpose Platform 1.0.0 device is prone to an unauthenticated device configuration vulnerability and client-side hidden functionality disclosure. An attacker can exploit this issue by sending unauthorized commands to the affected device, leading to unauthorized access and potential disclosure of hidden functionalities.
Mitigation:
To mitigate this vulnerability, it is recommended to restrict network access to the device, apply the principle of least privilege, and regularly monitor and audit device configurations for any unauthorized changes.