PT-2021-22962 · Unknown · Nlight Eclypse
Published
2021-09-17
·
Updated
2021-10-04
·
CVE-2021-40825
CVSS v3.1
8.6
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
nLight ECLYPSE (nECY) system Controllers versions prior to 1.17.21245.754
Description
The issue concerns a default key vulnerability in the nLight ECLYPSE (nECY) system Controllers. These controllers utilize an encrypted channel to secure SensorView configuration and monitoring software and nECY to nECY communications. However, the nECY does not force a change to the key upon the initial configuration of an affected device, making impacted devices at risk of exploitation. A remote attacker with IP access to an impacted device could submit lighting control commands to the nECY by leveraging the default key, potentially gaining the ability to modify lighting conditions or update the software on lighting devices. The impacted key is referred to as the
SensorView Password in the nECY nLight Explorer Interface and the Gateway Password in the SensorView application.Recommendations
For versions prior to 1.17.21245.754, update the software to version 1.17.21245.754 or later to resolve the default key vulnerability. As a temporary workaround, consider changing the default key, referred to as the
SensorView Password or Gateway Password, to a unique and secure key to prevent exploitation. Restrict IP access to impacted devices to minimize the risk of exploitation until the software can be updated.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nlight Eclypse