Improper Authentication in Sensormatic Electronics products - CVE-2023-3127

 

Improper Authentication in Sensormatic Electronics products - CVE-2023-3127

Published: July 13, 2023


Vulnerability identifier: #VU78237
CSH Severity: Medium
CVSS v4: 6.1 [CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-3127
CWE-ID: CWE-287
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to an error in when processing authentication requests. A remote attacker on the local network can bypass authentication process and gain unauthorized access to the application.


Affected software

iSTAR Ultra
iSTAR Ultra LT
iSTAR Ultra G2
iSTAR Edge G2

How to mitigate CVE-2023-3127

Install updates from vendor's website.

iSTAR Ultra - update to 6.9.2 CU01
iSTAR Ultra LT - update to 6.9.2 CU01
iSTAR Ultra G2 - update to 6.9.2 CU01
iSTAR Edge G2 - update to 6.9.2 CU01

External References

Related Security Bulletins