About Us - Hero image

Vulnerability Advisories

← Back to Vulnerability Advisories
CVE-2023-36670 High

CVE-2023-36670: Kratos NGC Indoor Unit (IDU) Command Injection Vulnerability

Advisory ID CVE-2023-36670
Severity High
Publish Date June 27, 2023
Affected Products Kratos NGC Indoor Unit (NGC-IDU)
Credit / Discoverer

Paul Noalhyt, Red Balloon Security

Synopsis

Kratos NGC Indoor Unit (IDU) command injection vulnerability

Overview & Description

Kratos NGC Indoor Unit (IDU) command injection vulnerability. Remotely exploitable command injection vulnerability found on the Kratos NGC-IDU version 9.1.0.4.

Solution & Remediation

Solution

This issue cannot be resolved in NGC IDU, which is End-of-Life effective August 1st, 2023. Kratos encourages customers to use good physical security of the ODU by locking the unit enclosure to prevent unauthorized access. The IDU should be installed on a trusted network, and access should be limited to authorized hosts using iptables/firewall.

Fix & Mitigate

Upgrade to latest NGC IDU product: NGC2-IDU SW & HW Accessories.

Ready to Get Started?

A family of solutions that enable the digital transformation of ground systems.

Contact Us