vendor:
Elber ESE DVB-S/S2 Satellite Receiver
by:
Gjoko 'LiquidWorm' Krstic
6.1
CVSS
HIGH
Unauthenticated Device Configuration and Hidden Functionality Disclosure
16
CWE
Product Name: Elber ESE DVB-S/S2 Satellite Receiver
Affected Version From: 1.5.179 Revision 904
Affected Version To: 1.229 Revision 440
Patch Exists: NO
Related CWE:
CPE: h:elber:ese_dvb-s_s2_satellite_receiver:1.5.179
Platforms Tested: NBFM Controller, embOS/IP
2023
Elber ESE DVB-S/S2 Satellite Receiver 1.5.x Device Configuration Vulnerability
The Elber ESE DVB-S/S2 Satellite Receiver 1.5.x devices suffer from an unauthenticated device configuration and client-side hidden functionality disclosure. An attacker can exploit this vulnerability to manipulate device configuration settings and reveal hidden functionalities without authentication.
Mitigation:
To mitigate this vulnerability, it is recommended to restrict network access to the device, apply the principle of least privilege, and regularly monitor and audit device configurations for unauthorized changes.