In ATI Systems Emergency Mass Notification Systems (HPSS16, HPSS32, MHPSS, and ALERT4000) devices, a missing encryption of sensitive data vulnerability caused by specially crafted malicious radio transmissions may allow an attacker to remotely trigger false alarms.
The product does not encrypt sensitive or critical information before storage or transmission.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/103721 | third party advisory vdb entry |
https://ics-cert.us-cert.gov/advisories/ICSA-18-100-01 | mitigation third party advisory us government resource |