Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Paul Noalhyt

Researcher fromRed Balloon Security
#13679of 53,633
19.6Total CVSS
Vulnerabilities · 2
Critical
2
PT-2023-25670
9.8
2023-07-18
Kratos · Kratos Ngc Indoor Unit · CVE-2023-36669
**Name of the Vulnerable Software and Affected Versions** Kratos NGC Indoor Unit (IDU) versions prior to 11.4 **Description** The issue allows remote attackers to obtain arbitrary control of the IDU/ODU system due to missing authentication for a critical function. Attackers with layer-3 network access to the IDU can impersonate the Touch Panel Unit (TPU) by sending crafted TCP requests to the IDU. **Recommendations** For versions prior to 11.4, update to version 11.4 or later to resolve the issue. As a temporary workaround, consider restricting layer-3 network access to the IDU to minimize the risk of exploitation.
PT-2023-25672
9.8
2023-07-18
Kratos · Kratos Ngc-Idu · CVE-2023-36670
**Name of the Vulnerable Software and Affected Versions** Kratos NGC-IDU version 9.1.0.4 **Description** A remotely exploitable command injection issue was discovered, allowing an attacker to execute arbitrary Linux commands as root by sending crafted TCP requests to the device. **Recommendations** For Kratos NGC-IDU version 9.1.0.4, as a temporary workaround, consider restricting access to the device to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.