MachineSense FeverWarn Raspberry Pi-based devices lack input sanitization, which could allow an attacker on an adjacent network to send a message running commands or could overflow the stack.











Fixes

Solution

No solution given by the vendor.


Workaround

FeverWarn and the associated cloud service were pandemic-specific products for elevated body temperature scanning, discontinued by MachineSense prior to the end of the pandemic. They are no longer available, and there will be no future availability or upgrades. MachineSense is not aware of any current users of FeverWarn. Users of the affected product are encouraged to contact MachineSense https://machinesense.com/pages/about-machinesense  for additional information.

History

Thu, 17 Oct 2024 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2024-10-17T16:03:08.150Z

Reserved: 2023-11-30T20:38:25.978Z

Link: CVE-2023-49610

cve-icon Vulnrichment

Updated: 2024-08-02T22:01:25.920Z

cve-icon NVD

Status : Modified

Published: 2024-02-01T23:15:10.003

Modified: 2024-11-21T08:33:38.053

Link: CVE-2023-49610

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.