PT-2023-32575 · Unknown · Syrus4 Iot Gateway

Yashin Mehaboobe

·

Publicado

2023-11-21

·

Atualizado

2023-12-09

·

CVE-2023-6248

CVSS v3.1

10

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Syrus4 IoT Gateway (affected versions not specified)
Description The Syrus4 IoT gateway has an unsecured MQTT server, allowing a remote unauthenticated attacker to execute arbitrary commands on connected devices. This exposes location, video, and diagnostic data from each device. An attacker with the server's IP address can connect and perform various operations, including getting location data, sending CAN bus messages, immobilizing vehicles, accessing live video, and sending audio messages to drivers. The issue potentially affects thousands of vehicles.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Cleartext Transmission of Sensitive Information

Improper Authentication

Information Disclosure

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-6248

Produtos afetados

Syrus4 Iot Gateway