vendor:
Elber Wayber Analog/Digital Audio STL 4.00
by:
Gjoko 'LiquidWorm' Krstic
6.1
CVSS
HIGH
Unauthenticated Device Configuration and Client-side Hidden Functionality Disclosure
798
CWE
Product Name: Elber Wayber Analog/Digital Audio STL 4.00
Affected Version From: Version 1.0.0 Revision 1202
Affected Version To: Version 3.0.0 Revision 1553
Patch Exists: NO
Related CWE:
CPE: a:elber_s.r.l.:analog_digital_audio_stl:4.00
Platforms Tested: NBFM Controller, embOS/IP
2023
Elber Wayber Analog/Digital Audio STL 4.00 Device Configuration Vulnerability
Elber Wayber Analog/Digital Audio STL 4.00 devices are vulnerable to unauthenticated device configuration and disclosure of hidden functionalities on the client-side. An attacker can exploit this issue to modify device configurations without authentication and reveal hidden functionalities that are not intended for regular users.
Mitigation:
To mitigate this vulnerability, it is recommended to restrict access to the device configuration interfaces and implement proper authentication mechanisms. Regularly updating the firmware to the latest version provided by Elber S.r.l. can also help in addressing this issue.