Yellowbrik PEC-1864 authentication bypass
Published Apr 6, 2023
9.8
CRITICALCVSS 3.1
EPSS 0.45%
Description
Yellobrik PEC-1864 implements authentication checks via javascript in the frontend interface. When the device can be accessed over the network an attacker could bypass authentication.
This would allow an attacker to : - Change the password, resulting in a DOS of the users
- Change the streaming source, compromising the integrity of the stream
- Change the streaming destination, compromising the confidentiality of the stream
This issue affects Yellowbrik: PEC 1864. No patch has been issued by the manufacturer as this model was discontinued.
Affected products
-
- Version PEC 1864StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Lynx Technik AG | Yellowbrik | affected |
|
- n/a
Running on/with
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
isolate the PEC-1864 behind a firewall disallowing any traffic on the web interface, do not allow access from internet.
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-12768 Advisory
- https://support.lynx-technik.com/support/solutions/articles/1000317081-pec-1864-web-ui-for-configuration Vendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-12768 | Advisory | |
| https://support.lynx-technik.com/support/solutions/articles/1000317081-pec-1864-web-ui-for-configuration | Vendor Advisory |
Change history (0)
No recorded changes yet.