PT-2024-39765 · Vimesa · Vimesa Vhf/Fm Transmitter Blue Plus

Gjoko Krstic

·

Published

2024-10-24

·

Updated

2024-11-10

·

CVE-2024-9692

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions VIMESA VHF/FM Transmitter Blue Plus (affected versions not specified)
Description The issue concerns a Denial-of-Service (DoS) vulnerability. An unauthenticated attacker can send an unauthorized HTTP GET request to the unprotected endpoint 'doreboot' and restart the transmitter operations.
Recommendations As a temporary workaround, consider restricting access to the 'doreboot' endpoint to prevent unauthorized restarts of the transmitter operations. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2024-9692

Affected Products

Vimesa Vhf/Fm Transmitter Blue Plus