Description
MachineSense FeverWarn Raspberry Pi-based devices lack input sanitization, which could allow an attacker on an adjacent network to send a message running commands or could overflow the stack.
Problem types
CWE-20 Improper Input Validation
Product status
ESP32
RaspberryPi
DataHub RaspberryPi
Credits
Vera Mens of Claroty Research reported these vulnerabilities to CISA.
References
www.cisa.gov/news-events/ics-advisories/icsa-24-025-01
machinesense.com/pages/about-machinesense