PT-2024-1435 · Unknown · Feverwarn Esp32+3

Vera Mens

·

Published

2024-01-25

·

Updated

2024-08-02

·

CVE-2023-49115

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions MachineSense devices (affected versions not specified) FeverWarn ESP32 (affected versions not specified) FeverWarn RaspberryPi (affected versions not specified) FeverWarn DataHub RaspberryPi (affected versions not specified)
Description The issue is related to the lack of authentication procedure for a critical function when processing MQTT messages, which can allow a remote attacker to gain unauthorized access to protected information. MachineSense devices use unauthenticated MQTT messaging to monitor devices and allow remote viewing of sensor data by users.
Recommendations For MachineSense devices, consider disabling the use of unauthenticated MQTT messaging until a proper authentication mechanism is implemented. For FeverWarn ESP32, FeverWarn RaspberryPi, and FeverWarn DataHub RaspberryPi, restrict access to critical functions that process MQTT messages until an authentication procedure is put in place. As a temporary workaround, consider implementing additional security measures to minimize the risk of exploitation, such as restricting remote access to sensor data. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authentication

Weakness Enumeration

Related Identifiers

BDU:2024-00910
CVE-2023-49115

Affected Products

Feverwarn Datahub Raspberrypi
Feverwarn Esp32
Feverwarn Raspberrypi
Machinesense