PT-2019-8140 · Fermax · Fermax Outdoor Panel

Dizijoyjoy

·

Published

2019-12-24

·

Updated

2020-01-08

·

CVE-2017-16778

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Fermax Outdoor Panel (affected versions not specified)
Description An access control weakness in the DTMF tone receiver allows physical attackers to inject a Dual-Tone-Multi-Frequency (DTMF) tone to invoke an access grant, enabling unauthorized physical access to a restricted floor or level. Normally, only a residential unit owner can allow such access. However, due to incorrect access control, an attacker can inject the tone via the speaker unit to gain access. This can be achieved by injecting a loud DTMF tone representing '1' and a long '#' (697 Hz and 1209 Hz, followed by 941 Hz and 1477 Hz).
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-16778

Affected Products

Fermax Outdoor Panel