PT-2019-8140 · Fermax · Fermax Outdoor Panel
Dizijoyjoy
·
Published
2019-12-24
·
Updated
2020-01-08
·
CVE-2017-16778
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Fermax Outdoor Panel (affected versions not specified)
Description
An access control weakness in the DTMF tone receiver allows physical attackers to inject a Dual-Tone-Multi-Frequency (DTMF) tone to invoke an access grant, enabling unauthorized physical access to a restricted floor or level. Normally, only a residential unit owner can allow such access. However, due to incorrect access control, an attacker can inject the tone via the speaker unit to gain access. This can be achieved by injecting a loud DTMF tone representing '1' and a long '#' (697 Hz and 1209 Hz, followed by 941 Hz and 1477 Hz).
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fermax Outdoor Panel