ZDI-20-805: C-MORE HMI EA9 Authentication Bypass Vulnerability
This vulnerability allows remote attackers to bypass authentication on affected installations of C-MORE HMI EA9 touch screen panels. Authentication is not required to exploit this vulnerability. The specific flaw exists within the authentication mechanism. The issue is due to insufficient authentication on post-authentication requests. An attacker can leverage this vulnerability to escalate privileges to resources normally protected from unauthenticated users.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-20-805?
The severity of ZDI-20-805 is considered high due to the ability of remote attackers to bypass authentication.
How do I fix ZDI-20-805?
To fix ZDI-20-805, you should apply the latest firmware update provided by C-MORE for HMI EA9 panels.
What types of systems are affected by ZDI-20-805?
ZDI-20-805 affects C-MORE HMI EA9 touch screen panels specifically.
Can ZDI-20-805 be exploited without authentication?
Yes, ZDI-20-805 can be exploited without requiring any authentication.
What symptoms indicate the existence of ZDI-20-805 on a system?
There may be no specific symptoms as ZDI-20-805 allows unauthorized access without detection.