PT-2022-11164 · Unknown · Ais-Bw80H-00
Published
2022-02-25
·
Updated
2022-03-08
·
CVE-2021-40043
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
AIS-BW80H-00 versions prior to 9.0.3.4(H100SP13C00)
Description
The issue allows for laser command injection, which can be exploited by attackers to execute voice commands on the device. This can happen when the device is visually exploitable. The devices cannot effectively defend against external malicious interference.
Recommendations
For versions prior to 9.0.3.4(H100SP13C00), update to version 9.0.3.4(H100SP13C00) or later to resolve the issue.
Fix
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ais-Bw80H-00