ZDI-CAN-10182: C-MORE HMI EA9 Authentication Bypass Vulnerability
This vulnerability allows remote attackers to bypass authentication on affected installations of C-MORE HMI EA9 touch screen panels. Authentication is not required to exploit this vulnerability. The specific flaw exists within the authentication mechanism. The issue is due to insufficient authentication on post-authentication requests. An attacker can leverage this vulnerability to escalate privileges to resources normally protected from unauthenticated users.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-10182?
The severity of ZDI-CAN-10182 is critical due to the potential for remote attackers to bypass authentication.
How do I fix ZDI-CAN-10182?
To mitigate ZDI-CAN-10182, ensure that your C-MORE HMI EA9 touch screen panels are updated to the latest firmware provided by the vendor.
What type of vulnerability is ZDI-CAN-10182?
ZDI-CAN-10182 is an authentication bypass vulnerability in C-MORE HMI EA9 touch screen panels.
Who is affected by ZDI-CAN-10182?
All installations of C-MORE HMI EA9 touch screen panels are affected by ZDI-CAN-10182.
Can ZDI-CAN-10182 be exploited remotely?
Yes, ZDI-CAN-10182 can be exploited remotely without requiring authentication.