SB2021021701 - Multiple vulnerabilities in Hamilton-T1
Published: February 17, 2021
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 3 secuirty vulnerabilities.
1) Use of hard-coded credentials (CVE-ID: CVE-2020-27278)
The vulnerability allows a local attacker to gain full access to vulnerable system.
The vulnerability exists due to presence of hard-coded credentials in application code. An attacker with physical access can obtain admin privileges for the device’s configuration interface.
2) Missing XML Validation (CVE-ID: CVE-2020-27282)
The vulnerability allows a local user to compromise the target system.
The vulnerability exists due to an XML validation vulnerability in the ventilator. An authenticated attacker with physical access can upload specially crafted configuration files and render the device persistently unusable.
3) Information disclosure (CVE-ID: CVE-2020-27290)
The vulnerability allows a local user to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output by the application. An authenticated attacker with physical access can gain unauthorized access to sensitive information on the system.
Remediation
Cybersecurity Help is not aware of any official remediation provided by the vendor.