PT-2020-15628 · Moog · Moog Exo Series
Gabriel Gonzalez
+3
·
Published
2020-08-21
·
Updated
2021-07-21
·
CVE-2020-24051
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Moog EXO Series versions EXVF5C-2 and EXVP7C2-3
Description
A security issue was found in the Moog EXO Series units that support the ONVIF interoperability protocol. The authentication check for certain ONVIF operations can be bypassed, allowing an attacker to execute privileged operations without authentication. This could enable the creation of a new Administrator user.
Recommendations
For Moog EXO Series versions EXVF5C-2 and EXVP7C2-3, as a temporary workaround, consider disabling the ONVIF protocol until a patch is available. Restrict access to privileged operations to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.
Exploit
Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Moog Exo Series