PT-2022-24489 · Patlite · Patlite Nh-Fb

Published

2022-08-29

·

Updated

2024-08-03

·

CVE-2022-38625

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Patlite NH-FB versions 1.46 and below
Description The issue is related to insufficient firmware validation during the upgrade firmware file upload process. This allows authenticated attackers to create and upload their own custom-built firmware and inject malicious code. The vendor considers this a design choice rather than a vulnerability.
Recommendations For Patlite NH-FB versions 1.46 and below, as a temporary workaround, consider restricting access to the firmware upgrade process to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.

Fix

Insufficient Verification of Data Authenticity

Weakness Enumeration

Related Identifiers

CVE-2022-38625

Affected Products

Patlite Nh-Fb