vendor:
VIMESA VHF/FM Transmitter Blue Plus
by:
Gjoko 'LiquidWorm' Krstic
6.1
CVSS
HIGH
Remote Denial of Service
400
CWE
Product Name: VIMESA VHF/FM Transmitter Blue Plus
Affected Version From: 9.7.2001
Affected Version To: 9.7.2001
Patch Exists: NO
Related CWE:
CPE: a:video_medios:vimesa_vhf_fm_transmitter_blue_plus:9.7.1
Platforms Tested: lighttpd/1.4.32
2023
VIMESA VHF/FM Transmitter Blue Plus 9.7.1 (doreboot) Remote Denial Of Service
The VIMESA VHF/FM Transmitter Blue Plus 9.7.1 is vulnerable to a Denial of Service (DoS) attack. By sending an unauthorized HTTP GET request to the unprotected endpoint 'doreboot', an unauthenticated attacker can restart the transmitter operations, causing a denial of service.
Mitigation:
To mitigate this vulnerability, it is recommended to restrict access to the 'doreboot' endpoint and implement proper authentication mechanisms to prevent unauthorized access.