
CVE-2023-3127 – Improper Authentication in iSTAR
https://notcve.org/view.php?id=CVE-2023-3127
11 Jul 2023 — An unauthenticated user could log into iSTAR Ultra, iSTAR Ultra LT, iSTAR Ultra G2, and iSTAR Edge G2 with administrator rights. • https://www.cisa.gov/news-events/ics-advisories/icsa-23-192-02 • CWE-287: Improper Authentication •

CVE-2022-21941 – iSTAR Ultra
https://notcve.org/view.php?id=CVE-2022-21941
31 Aug 2022 — All versions of iSTAR Ultra prior to version 6.8.9.CU01 are vulnerable to a command injection that could allow an unauthenticated user root access to the system. Todas las versiones de iSTAR Ultra anteriores a la versión 6.8.9.CU01 son vulnerables a una inyección de comandos que podría permitir a un usuario no autentificado el acceso a la raíz del sistema • https://www.cisa.gov/uscert/ics/advisories/icsa-22-242-11 • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') •

CVE-2017-17704 – iStar Ultra / IP-ACM Boards Fixed AES Key
https://notcve.org/view.php?id=CVE-2017-17704
20 Dec 2017 — A door-unlocking issue was discovered on Software House iStar Ultra devices through 6.5.2.20569 when used in conjunction with the IP-ACM Ethernet Door Module. The communications between the IP-ACM and the iStar Ultra is encrypted using a fixed AES key and IV. Each message is encrypted in CBC mode and restarts with the fixed IV, leading to replay attacks of entire messages. There is no authentication of messages beyond the use of the fixed AES key, so message forgery is also possible. Se ha descubierto un pr... • https://systemoverlord.com/2017/12/18/cve-2017-17704-broken-cryptography-in-istar-ultra-ip-acm-by-software-house.html • CWE-330: Use of Insufficiently Random Values •