Description
Positron Broadcast Signal Processor TRA7005 v1.20 is vulnerable to an authentication bypass exploit that could allow an attacker to have unauthorized access to protected areas of the application.
Published: 2024-07-25
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

Positron has not responded to requests to work with CISA to mitigate this vulnerability. Users of affected versions of TRA7005 are invited to contact Positron customer support https://www.positron.it/contatti/  for additional information.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-48028 Positron Broadcast Signal Processor TRA7005 v1.20 is vulnerable to an authentication bypass exploit that could allow an attacker to have unauthorized access to protected areas of the application.
History

Mon, 26 Aug 2024 17:00:00 +0000

Type Values Removed Values Added
First Time appeared Positron
Positron tra7005
Positron tra7005 Firmware
Weaknesses CWE-306
CPEs cpe:2.3:h:positron:tra7005:*:*:*:*:*:*:*:*
cpe:2.3:o:positron:tra7005_firmware:1.20:*:*:*:*:*:*:*
Vendors & Products Positron
Positron tra7005
Positron tra7005 Firmware
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Positron Tra7005 Tra7005 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2024-08-01T21:45:38.372Z

Reserved: 2024-07-23T02:44:43.814Z

Link: CVE-2024-7007

cve-icon Vulnrichment

Updated: 2024-08-01T21:45:38.372Z

cve-icon NVD

Status : Modified

Published: 2024-07-25T17:15:11.837

Modified: 2024-11-21T09:50:44.713

Link: CVE-2024-7007

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses