Lucene search

K
jvnJapan Vulnerability NotesJVN:77203800
HistoryFeb 29, 2024 - 12:00 a.m.

JVN#77203800: OET-213H-BTS1 missing authorization check in the initial configuration

2024-02-2900:00:00
Japan Vulnerability Notes
jvn.jp
4
digital temperature measurement
face recognition terminal
zhejiang uniview technologies co. ltd
atsumi electric co. ltd
authorization check
api requests
insecure configuration
cwe-1188
http authentication
vendor status
vulnerable products
japan.

6.8 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

15.7%

OET-213H-BTS1 is a digital temperature measurement and face recognition terminal, developed by Zhejiang Uniview Technologies Co.,Ltd and provided by Atsumi Electric Co., Ltd.
The initial configuration of the product is ​insecure (CWE-1188), it does not perform an authorization check when processing the API requests.

Impact

The product may be configured and controlled from within the adjacent network without authentication.

Solution

Update the configuration
You can enable HTTP authentication.

For more details, refer to the information in the Vendor Status section below.

Products Affected

This vulnerability is reported for the following products sold in Japan by Atsumi Electric co., Ltd.

  • OET-213H-BTS1

6.8 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

15.7%

Related for JVN:77203800