PT-2024-1431 · Machinesense · Feverwarn Raspberrypi+3
Vera Mens
·
Published
2024-01-25
·
Updated
2024-08-02
·
CVE-2023-47867
CVSS v3.1
8.8
High
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
MachineSense FeverWarn devices (affected versions not specified)
FeverWarn ESP32 (affected versions not specified)
FeverWarn RaspberryPi (affected versions not specified)
FeverWarn DataHub RaspberryPi (affected versions not specified)
Description
The issue is related to inadequate access control when handling Wi-Fi nodes, which could allow a remote attacker to elevate their privileges. Attackers within range can connect to the device's web services and compromise it.
Recommendations
For MachineSense FeverWarn devices, restrict access to the device's web services to minimize the risk of exploitation.
For FeverWarn ESP32, FeverWarn RaspberryPi, and FeverWarn DataHub RaspberryPi, consider implementing proper access control measures for Wi-Fi nodes until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Feverwarn Datahub Raspberrypi
Feverwarn Esp32
Feverwarn Raspberrypi
Machinesense Feverwarn