Описание
Missing Authentication for a Critical Function within the Kratos NGC Indoor Unit (IDU) before 11.4 allows remote attackers to obtain arbitrary control of the IDU/ODU system. Any attacker with layer-3 network access to the IDU can impersonate the Touch Panel Unit (TPU) within the IDU by sending crafted TCP requests to the IDU.
Ссылки
- Product
- Vendor Advisory
- Product
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 11.4 (исключая)
Одновременно
cpe:2.3:o:kratosdefense:ngc_indoor_unit_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:kratosdefense:ngc_indoor_unit:-:*:*:*:*:*:*:*
EPSS
Процентиль: 44%
0.00216
Низкий
9.8 Critical
CVSS3
Дефекты
CWE-306
Связанные уязвимости
CVSS3: 9.8
github
больше 2 лет назад
Missing Authentication for a Critical Function within the Kratos NGC Indoor Unit (IDU) before 11.4 allows remote attackers to obtain arbitrary control of the IDU/ODU system. Any attacker with layer-3 network access to the IDU can impersonate the Touch Panel Unit (TPU) within the IDU by sending crafted TCP requests to the IDU.
EPSS
Процентиль: 44%
0.00216
Низкий
9.8 Critical
CVSS3
Дефекты
CWE-306