PT-2025-7797 · Novachron Zeitsysteme Gmbh & Co. Kg · Smart Time Plus

Secure77

·

Published

2025-02-24

·

Updated

2025-02-25

·

CVE-2024-53542

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions NovaCHRON Zeitsysteme GmbH & Co. KG Smart Time Plus versions 8.x through 8.6
Description The issue concerns incorrect access control in the component /iclock/Settings?restartNCS=1, allowing attackers to arbitrarily restart the NCServiceManger via a crafted GET request.
Recommendations For versions 8.x through 8.6, consider disabling access to the /iclock/Settings?restartNCS=1 component until a patch is available. Restrict access to the NCServiceManger to minimize the risk of exploitation.

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2024-53542

Affected Products

Smart Time Plus