CVE-2023-36669
CRITICALKratos NGC Indoor Unit Firmware < 11.4 - Unauthenticated Remote Control via TPU Impersonation
Title source: llmDescription
Missing Authentication for a Critical Function within the Kratos NGC Indoor Unit (IDU) before 11.4 allows remote attackers to obtain arbitrary control of the IDU/ODU system. Any attacker with layer-3 network access to the IDU can impersonate the Touch Panel Unit (TPU) within the IDU by sending crafted TCP requests to the IDU.
References (2)
Core 2
Core References
Product
https://kratosdefense.com
Scores
CVSS v3
9.8
EPSS
0.0066
EPSS Percentile
46.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
total
Details
CWE
CWE-306
Status
published
Products (1)
kratosdefense/ngc_indoor_unit_firmware
< 11.4
Published
Jul 18, 2023
Tracked Since
Feb 18, 2026