vendor:
Reble610 M/ODU XPIC IP-ASI-SDH Microwave Link Device
by:
Gjoko 'LiquidWorm' Krstic
6.1
CVSS
HIGH
Unauthenticated Device Configuration and Client-Side Hidden Functionality Disclosure
16
CWE
Product Name: Reble610 M/ODU XPIC IP-ASI-SDH Microwave Link Device
Affected Version From: 0.01 Revision 0
Affected Version To: 0.01 Revision 0
Patch Exists: NO
Related CWE:
CPE: h:elber_s.r.l.:reble610_firmware:0.01
Platforms Tested: NBFM Controller, embOS/IP
2023
Elber Reble610 M/ODU XPIC IP-ASI-SDH Microwave Link Device Configuration Vulnerability
The Elber Reble610 M/ODU XPIC IP-ASI-SDH Microwave Link Device allows an attacker to configure the device without authentication and reveals hidden functionality on the client-side. By exploiting this vulnerability, an unauthorized user can manipulate device settings and access undisclosed features.
Mitigation:
To mitigate this vulnerability, it is recommended to restrict network access to the device, apply proper authentication mechanisms, and regularly monitor for any unauthorized configuration changes or activities.