PT-2023-21845 · Omicron · Omicron Stationscout+1

Hendrik Schwartke

·

Published

2023-03-23

·

Updated

2023-03-28

·

CVE-2023-28610

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OMICRON StationGuard versions prior to 2.21 OMICRON StationScout versions prior to 2.21
Description The update process can be exploited by providing a modified firmware update image, allowing a remote attacker to gain root access to the system.
Recommendations For OMICRON StationGuard versions prior to 2.21, update to version 2.21 or later to resolve the issue. For OMICRON StationScout versions prior to 2.21, update to version 2.21 or later to resolve the issue.

Fix

Improper Verification of Cryptographic Signature

Weakness Enumeration

Related Identifiers

CVE-2023-28610

Affected Products

Omicron Stationguard
Omicron Stationscout