CyberData 011209 Intercom could allow an unauthenticated user access to the Web Interface through an alternate path.
The error classified as CWE-288 (Authentication Bypass Using an Alternate Path or Channel) lies in the fact that the authentication mechanism is not enforced for all access paths to the device's web interface. An attacker can reach the protected management interface by bypassing the standard login procedure through an unprotected alternate URL path or access channel. The attack requires no permissions, user interaction, or complex conditions — network access to the device is sufficient.
An unauthenticated attacker gains full access to the device's web interface, which may enable takeover of intercom configuration, modification of SIP settings, disruption of emergency communications, or further network activities.
Apply patches available from the manufacturer according to references. Detailed information about firmware updates is contained in the CISA ICS-CERT advisory numbered ICSA-25-155-01 (https://www.cisa.gov/news-events/ics-advisories/icsa-25-155-01). Until the patch is deployed, it is recommended to restrict network access to the device's management interface exclusively to trusted hosts/networks, for example through firewall or network segmentation.
CyberData 011209 SIP Emergency Intercom and related firmware software (versions indicated in manufacturer references / CISA advisory ICSA-25-155-01)
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XCyberdata 011209 Sip Emergency Intercom
HWCyberdataall versionsCyberdata 011209 Sip Emergency Intercom Firmware
OSCyberdata< 22.0.1
Related vulnerabilities
CyberData 011209 SIP Intercom — nieautoryzowane przesyłanie plików (path traversal)
CyberData 011209 Intercom exposes features that could allow an unauthenticated to gain access and cause a...
CyberData 011209 Intercom does not properly store or protect web server admin credentials.
CyberData 011209 Intercom could allow an unauthenticated user to gather sensitive information through blind SQ...