PT-2023-7057 · Quantum · Quantum Hd Unity Interface+4
Jim Reprogle
·
Published
2023-11-09
·
Updated
2025-12-16
·
CVE-2023-4804
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Quantum HD Unity products (affected versions not specified)
Quantum HD Unity Compressor (affected versions not specified)
Quantum HD Unity AcuAir (affected versions not specified)
Quantum HD Unity Engine Room (affected versions not specified)
Quantum HD Unity Interface (affected versions not specified)
Description
An unauthorized user could access debug features in Quantum HD Unity products that were accidentally exposed. The vulnerability exists due to the incorrect inclusion of debug mode for certain services. Exploitation of the vulnerability may allow a remote attacker to execute arbitrary commands by accessing the device's debug features. The potentially vulnerable equipment is used worldwide by suppliers in the food industry and critical manufacturing sectors. The issue was discovered by an independent researcher and was fixed in each of the affected control panels.
Recommendations
For Quantum HD Unity products, consider disabling the debug features until a patch is available.
For Quantum HD Unity Compressor, AcuAir, Engine Room, and Interface, restrict access to the debug mode to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Quantum Hd Unity
Quantum Hd Unity Acuair
Quantum Hd Unity Compressor
Quantum Hd Unity Engine Room
Quantum Hd Unity Interface