vendor:
ESE DVB-S/S2 Satellite Receiver
by:
Gjoko 'LiquidWorm' Krstic
6.1
CVSS
HIGH
Authentication Bypass
287
CWE
Product Name: ESE DVB-S/S2 Satellite Receiver
Affected Version From: 1.5.179 Revision 904
Affected Version To: 1.229 Revision 440
Patch Exists: NO
Related CWE:
CPE: h:elber:ese_dvb-s_s2_satellite_receiver:1.5.179
Platforms Tested: NBFM Controller, embOS/IP
2023
Elber ESE DVB-S/S2 Satellite Receiver 1.5.x Authentication Bypass
The Elber ESE DVB-S/S2 Satellite Receiver 1.5.x devices are prone to an authentication bypass vulnerability due to unauthorized access to the password management function. By manipulating the set_pwd endpoint, attackers can change the password of any user, granting them unauthorized administrative access to critical parts of the application and compromising system security.
Mitigation:
To mitigate this vulnerability, it is recommended to restrict network access to the affected devices, implement strong password policies, and regularly update the firmware provided by Elber S.r.l.