PT-2024-1432 · Unknown · Feverwarn Esp32+3

Vera Mens

·

Published

2024-01-25

·

Updated

2024-08-02

·

CVE-2023-46706

CVSS v3.1

9.4

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions MachineSense devices (affected versions not specified) FeverWarn ESP32 (affected versions not specified) FeverWarn RaspberryPi (affected versions not specified) FeverWarn DataHub RaspberryPi (affected versions not specified)
Description The issue is related to the absence of an authentication procedure for a critical function in the microprogram software of FeverWarn systems, allowing a remote attacker to gain unauthorized access to protected information, execute arbitrary code, and gain full control over the device. Additionally, Multiple MachineSense devices have credentials that cannot be changed by the user or administrator.
Recommendations For MachineSense devices, consider restricting access to critical functions until a fix is available. For FeverWarn ESP32, FeverWarn RaspberryPi, and FeverWarn DataHub RaspberryPi, disable critical functions that lack authentication procedures as a temporary workaround. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Using Hardcoded Credentials

Weakness Enumeration

Related Identifiers

BDU:2024-00907
CVE-2023-46706

Affected Products

Feverwarn Datahub Raspberrypi
Feverwarn Esp32
Feverwarn Raspberrypi
Machinesense