vendor:
Elber Wayber Analog/Digital Audio STL
by:
Gjoko 'LiquidWorm'
6.1
CVSS
HIGH
Authentication Bypass
287
CWE
Product Name: Elber Wayber Analog/Digital Audio STL
Affected Version From: Version 1.0.0 Revision 1202
Affected Version To: Version 3.0.0 Revision 1553
Patch Exists: NO
Related CWE: Not assigned
CPE: a:elber_s.r.l.:wayber_analog_digital_audio_stl:3.0.0
Platforms Tested: NBFM Controller, embOS/IP
Not specified
Elber Wayber Analog/Digital Audio STL 4.00 Authentication Bypass
The Elber Wayber Analog/Digital Audio STL version 3.0.0 and below, including Firmware versions 4.00 Rev. 1501, 4.00 Rev. 1516, and 3.00 Rev. 1350, are vulnerable to an authentication bypass. By exploiting this vulnerability, an attacker can gain unauthorized access to the password management functionality, allowing them to change passwords for any user in the system. This unauthorized access compromises the security of the device.
Mitigation:
To mitigate this vulnerability, it is recommended to restrict network access to the affected devices, apply the principle of least privilege, and regularly update the firmware to the latest version.