Missing Authentication for a Critical Function within the...
Critical severity
Unreviewed
Published
Jul 18, 2023
to the GitHub Advisory Database
•
Updated Apr 4, 2024
Description
Published by the National Vulnerability Database
Jul 18, 2023
Published to the GitHub Advisory Database
Jul 18, 2023
Last updated
Apr 4, 2024
Missing Authentication for a Critical Function within the Kratos NGC Indoor Unit (IDU) before 11.4 allows remote attackers to obtain arbitrary control of the IDU/ODU system. Any attacker with layer-3 network access to the IDU can impersonate the Touch Panel Unit (TPU) within the IDU by sending crafted TCP requests to the IDU.
References