vendor:
Elber Signum DVB-S/S2 IRD
by:
Gjoko 'LiquidWorm' Krstic
6.1
CVSS
HIGH
Unauthenticated Device Configuration and Hidden Functionality Disclosure
200
CWE
Product Name: Elber Signum DVB-S/S2 IRD
Affected Version From: 1.166
Affected Version To: 1.999
Patch Exists: NO
Related CWE:
CPE: h:elber:srl:signum_dvb-s_s2_ird
Platforms Tested: NBFM Controller, embOS/IP
2023
Elber Signum DVB-S/S2 IRD Unauthenticated Configuration Disclosure
Elber Signum DVB-S/S2 IRD devices with affected versions 1.999, 1.317, 1.220, 1.217, 1.214, 1.193, 1.175, and 1.166 are prone to unauthenticated device configuration and client-side hidden functionality disclosure. An attacker can exploit this vulnerability to manipulate device configurations and reveal hidden functionalities without authentication.
Mitigation:
To mitigate this vulnerability, it is recommended to restrict network access to the device, implement strong authentication mechanisms, and regularly update to the latest firmware version.