Multiple Elber products suffer from an unauthenticated device configuration and client-side hidden functionality disclosure.
Fixes

Solution

No solution given by the vendor.


Workaround

Elber does not plan to mitigate these vulnerabilities because this equipment is either end of life or almost end of life. Users of affected versions of Elber Signum DVB-S/S2 IRD, Cleber/3 Broadcast Multi-Purpose Platform, Reble610 M/ODU XPIC IP-ASI-SDH, ESE DVB-S/S2 Satellite Receiver, and Wayber Analog/Digital Audio STL are invited to contact Elber customer support https://elber.it/en/elber-contacts.php for additional information.

History

Wed, 12 Feb 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 07 Feb 2025 00:00:00 +0000

Type Values Removed Values Added
Description Multiple Elber products suffer from an unauthenticated device configuration and client-side hidden functionality disclosure.
Title Elber Communications Equipment Hidden Functionality
Weaknesses CWE-912
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2025-02-12T19:41:07.552Z

Reserved: 2025-01-23T15:00:27.299Z

Link: CVE-2025-0675

cve-icon Vulnrichment

Updated: 2025-02-12T19:40:30.848Z

cve-icon NVD

Status : Received

Published: 2025-02-07T00:15:28.030

Modified: 2025-02-07T00:15:28.030

Link: CVE-2025-0675

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.