The update process in OMICRON StationGuard and OMICRON StationScout before 2.21 can be exploited by providing a modified firmware update image. This allows a remote attacker to gain root access to the system.
The product does not verify, or incorrectly verifies, the cryptographic signature for data.
Link | Tags |
---|---|
https://www.omicronenergy.com/en/support/product-security/ | vendor advisory |
https://www.omicronenergy.com/fileadmin/user_upload/website/files/product-security/osa-5.txt | vendor advisory |