« Volver al listado

CVE-2023-0750

Estado: ModificadaCrítica (9.8)—

Yellobrik PEC-1864 implements authentication checks via javascript in the frontend interface.  When the device can be accessed over the network an attacker could bypass authentication.

This would allow an attacker to : - Change the password, resulting in a DOS of the users

- Change the streaming source, compromising the integrity of the stream

- Change the streaming destination, compromising the confidentiality of the stream

This issue affects Yellowbrik: PEC 1864. No patch has been issued by the manufacturer as this model was discontinued.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-0750",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-0750",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-02-10T20:20:29.424789Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "vulnerability@ncsc.ch",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "vulnerability@ncsc.ch",
      "affectedData": [
        {
          "vendor": "Lynx Technik AG",
          "product": "Yellowbrik",
          "versions": [
            {
              "status": "affected",
              "version": "PEC 1864"
            }
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2023-04-06T14:15:07.913",
  "references": [
    {
      "url": "https://support.lynx-technik.com/support/solutions/articles/1000317081-pec-1864-web-ui-for-configuration",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "vulnerability@ncsc.ch"
    },
    {
      "url": "https://support.lynx-technik.com/support/solutions/articles/1000317081-pec-1864-web-ui-for-configuration",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "vulnerability@ncsc.ch",
      "description": [
        {
          "lang": "en",
          "value": "CWE-602"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-311"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Yellobrik PEC-1864 implements authentication checks via javascript in the frontend interface.  When the device can be accessed over the network an attacker could bypass authentication.\n\n\n\n\nThis would allow an attacker to : \n- Change the password, resulting in a DOS of the users\n\n- Change the streaming source, compromising the integrity of the stream\n\n- Change the streaming destination, compromising the confidentiality of the stream\n\n\n\n\n\n\n\n\nThis issue affects Yellowbrik: PEC 1864. No patch has been issued by the manufacturer as this model was discontinued.\n\n\n\n\n\n\n\n\n\n\n\n\n"
    }
  ],
  "lastModified": "2026-06-17T05:26:13.780",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:lynx-technik:yellobrik_pec_1864_firmware:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "77D15174-B673-4FC9-A6A1-3AFCF7887840"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:lynx-technik:yellobrik_pec_1864:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "3DE5B4F1-4DFB-4FD3-92D5-43152E93ACAD"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "vulnerability@ncsc.ch"
}