vendor:
Cleber/3 Broadcast Multi-Purpose Platform
by:
Gjoko 'LiquidWorm' Krstic
6.1
CVSS
HIGH
Authentication Bypass
287
CWE
Product Name: Cleber/3 Broadcast Multi-Purpose Platform
Affected Version From: 1.0.0 Revision 6258
Affected Version To: 1.0.0 Revision 7304
Patch Exists: NO
Related CWE:
CPE: a:elber_s.r.l.:cleber_broadcast_multi-purpose_platform:1.0.0
Platforms Tested: NBFM Controller, embOS/IP
Not specified
Elber Cleber/3 Broadcast Multi-Purpose Platform 1.0.0 Authentication Bypass
The Elber Cleber/3 Broadcast Multi-Purpose Platform 1.0.0 is vulnerable to an authentication bypass issue that allows attackers to gain unauthorized administrative access by manipulating the set_pwd endpoint to overwrite user passwords within the system. This exploit compromises the security of the device's system.
Mitigation:
To mitigate this vulnerability, it is recommended to apply the latest security patches provided by Elber S.r.l. and restrict network access to the device to trusted sources only.