PT-2024-23215 · Nec · Dt900+1

Gianluca Altomani

+1

·

Published

2024-05-09

·

Updated

2024-08-22

·

CVE-2024-3016

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions NEC Platforms DT900 and DT900S Series versions 5.0.0.0 through 5.3.4.4 NEC Platforms DT900 and DT900S Series versions 5.4.0.0 through 5.6.0.20
Description The issue allows an attacker to access non-documented system settings and change them via the local network without authentication.
Recommendations For versions 5.0.0.0 through 5.3.4.4, update to a version outside of this range to mitigate the risk. For versions 5.4.0.0 through 5.6.0.20, update to a version outside of this range to mitigate the risk. As a temporary workaround, consider restricting access to the system settings until a patch is available.

Fix

Hidden Functionality

Weakness Enumeration

Related Identifiers

CVE-2024-3016

Affected Products

Dt900
Dt900S