PT-2024-1431 · Machinesense · Feverwarn Raspberrypi+3

Vera Mens

·

Published

2024-01-25

·

Updated

2024-08-02

·

CVE-2023-47867

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MachineSense FeverWarn devices (affected versions not specified) FeverWarn ESP32 (affected versions not specified) FeverWarn RaspberryPi (affected versions not specified) FeverWarn DataHub RaspberryPi (affected versions not specified)
Description The issue is related to inadequate access control when handling Wi-Fi nodes, which could allow a remote attacker to elevate their privileges. Attackers within range can connect to the device's web services and compromise it.
Recommendations For MachineSense FeverWarn devices, restrict access to the device's web services to minimize the risk of exploitation. For FeverWarn ESP32, FeverWarn RaspberryPi, and FeverWarn DataHub RaspberryPi, consider implementing proper access control measures for Wi-Fi nodes until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Weakness Enumeration

Related Identifiers

BDU:2024-00906
CVE-2023-47867

Affected Products

Feverwarn Datahub Raspberrypi
Feverwarn Esp32
Feverwarn Raspberrypi
Machinesense Feverwarn