Vulnerability in Ingeteam's INGEPAC EF
Published Oct 2, 2023
8.6
HIGHCVSS 3.1
EPSS 0.66%
Description
Incorrect data input validation vulnerability, which could allow an attacker with access to the network to implement fuzzing techniques that would allow him to gain knowledge about specially crafted packets that would create a DoS condition through the MMS protocol when initiating communication, achieving a complete system reboot of the device and its services.
Affected products
-
Affected
- 9.0.22.6+6.1.1.22+5.3.1.1
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Ingeteam | Ingepac Fc5066 | unaffected | Affected
|
- 5.3.1.1
- 6.1.1.22
- 9.0.22.6
Running on/with
- n/a
-
Affected
- 9.0.22.6+6.1.1.22+5.3.1.1
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Ingeteam | Ingepac Fc5066 | unaffected | Affected
|
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
9.8.30.0 version and later.
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-44402 Advisory
- https://www.incibe.es/en/incibe-cert/notices/aviso-sci/multiple-vulnerabilities-ingeteam-products Third Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-44402 | Advisory | |
| https://www.incibe.es/en/incibe-cert/notices/aviso-sci/multiple-vulnerabilities-ingeteam-products | Third Party Advisory |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub
No data