{"id":122066,"date":"2024-05-15T14:56:42","date_gmt":"2024-05-15T14:56:42","guid":{"rendered":"https:\/\/bas-ip.com\/?page_id=122066"},"modified":"2024-11-05T10:20:36","modified_gmt":"2024-11-05T10:20:36","slug":"bsa-000001","status":"publish","type":"page","link":"https:\/\/bas-ip.com\/da\/bsa-000001\/","title":{"rendered":"BSA-000001"},"content":{"rendered":"<h2 class=\"wp-block-heading\" id=\"bsa-000001\">Oversigt<\/h2>\n\n\n\n<p>Der er opdaget et problem i flere BAS-IP intercom-enheder. Ved at f\u00e5 adgang til enhedens webinterface eller API kan en angriber f\u00e5 adgangskoder til enhedens RTSP-server og SIP-konto.<\/p>\n\n\n\n<p>BAS-IP klassificerer disse s\u00e5rbarheder som mellemstore og anbefaler, at kunderne opgraderer de ber\u00f8rte BAS-IP-modeller til den nyeste firmwareversion.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"risk-assessment\">Risikovurdering<\/h2>\n\n\n\n<p>En potentiel modstander skal have netv\u00e6rksadgang til enheden for at kunne udnytte s\u00e5rbarhederne. En modstander har brug for legitimationsoplysninger for at kunne kompromittere enheden. Risikoen afh\u00e6nger af, hvor eksponeret enheden er. Enheder, der vender mod internettet (f.eks. eksponeret via routerens port-forward), har en h\u00f8j risiko. Produkter, der anvendes p\u00e5 et beskyttet lokalt netv\u00e6rk, har en lavere risiko.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"risk-mitigation\">Begr\u00e6nsning af risici<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Det anbefales kraftigt at opgradere ber\u00f8rte modeller til den nyeste firmware.<\/li>\n\n\n\n<li>Det anbefales ikke at eksponere enheder direkte til internettet (port-forwarding).<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"affected-models-and-patched-firmware\">Ber\u00f8rte modeller og opdateret firmware<\/h2>\n\n\n\n<p>Liste over ber\u00f8rte modeller:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>AV-01D<\/li>\n\n\n\n<li>AV-01MD<\/li>\n\n\n\n<li>AV-01MFD<\/li>\n\n\n\n<li>AV-01ED<\/li>\n\n\n\n<li>AV-01KD<\/li>\n\n\n\n<li>AV-01BD<\/li>\n\n\n\n<li>AV-01KBD<\/li>\n\n\n\n<li>AV-02D<\/li>\n\n\n\n<li>AV-02IDE<\/li>\n\n\n\n<li>AV-02IDR<\/li>\n\n\n\n<li>AV-02IPD<\/li>\n\n\n\n<li>AV-02FDE<\/li>\n\n\n\n<li>AV-02FDR<\/li>\n\n\n\n<li>AV-03D<\/li>\n\n\n\n<li>AV-03BD<\/li>\n\n\n\n<li>AV-04AFD<\/li>\n\n\n\n<li>AV-04ASD<\/li>\n\n\n\n<li>AV-04FD<\/li>\n\n\n\n<li>AV-04SD<\/li>\n\n\n\n<li>AV-05FD<\/li>\n\n\n\n<li>AV-05SD<\/li>\n\n\n\n<li>AA-07BD<\/li>\n\n\n\n<li>AA-07BDI<\/li>\n\n\n\n<li>BA-04BD<\/li>\n\n\n\n<li>BA-04MD<\/li>\n\n\n\n<li>BA-08BD<\/li>\n\n\n\n<li>BA-08MD<\/li>\n\n\n\n<li>BA-12BD<\/li>\n\n\n\n<li>BA-12MD<\/li>\n\n\n\n<li>CR-02BD<\/li>\n<\/ul>\n\n\n\n<p>Opdateret firmware-version:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>3.9.2<\/li>\n<\/ul>","protected":false},"excerpt":{"rendered":"<p>Oversigt Der er opdaget et problem i flere BAS-IP intercom-enheder. Ved at f\u00e5 adgang til enhedens webinterface eller API kan en angriber f\u00e5 adgangskoder til enhedens RTSP-server og SIP-konto. BAS-IP klassificerer disse s\u00e5rbarheder som mellemstore og anbefaler, at kunderne opgraderer de ber\u00f8rte BAS-IP-modeller til den nyeste firmwareversion. Risikovurdering En potentiel modstander skal have netv\u00e6rksadgang til [&hellip;]<\/p>","protected":false},"author":3,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"inline_featured_image":false,"footnotes":""},"class_list":["post-122066","page","type-page","status-publish","hentry"],"acf":[],"_links":{"self":[{"href":"https:\/\/bas-ip.com\/da\/wp-json\/wp\/v2\/pages\/122066","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/bas-ip.com\/da\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/bas-ip.com\/da\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/bas-ip.com\/da\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/bas-ip.com\/da\/wp-json\/wp\/v2\/comments?post=122066"}],"version-history":[{"count":1,"href":"https:\/\/bas-ip.com\/da\/wp-json\/wp\/v2\/pages\/122066\/revisions"}],"predecessor-version":[{"id":122067,"href":"https:\/\/bas-ip.com\/da\/wp-json\/wp\/v2\/pages\/122066\/revisions\/122067"}],"wp:attachment":[{"href":"https:\/\/bas-ip.com\/da\/wp-json\/wp\/v2\/media?parent=122066"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}