{"id":122075,"date":"2024-05-15T14:56:42","date_gmt":"2024-05-15T14:56:42","guid":{"rendered":"https:\/\/bas-ip.com\/?page_id=122075"},"modified":"2024-11-05T10:28:18","modified_gmt":"2024-11-05T10:28:18","slug":"bsa-000001","status":"publish","type":"page","link":"https:\/\/bas-ip.com\/fr\/bsa-000001\/","title":{"rendered":"BSA-000001"},"content":{"rendered":"<h2 class=\"wp-block-heading\" id=\"bsa-000001\">Vue d&rsquo;ensemble<\/h2>\n\n\n\n<p>Un probl\u00e8me a \u00e9t\u00e9 d\u00e9couvert dans plusieurs dispositifs d&rsquo;interphone BAS-IP. En acc\u00e9dant \u00e0 l&rsquo;interface web ou \u00e0 l&rsquo;API de l&rsquo;appareil, un pirate peut obtenir les mots de passe du serveur RTSP et du compte SIP de l&rsquo;appareil.<\/p>\n\n\n\n<p>BAS-IP classe ces vuln\u00e9rabilit\u00e9s comme moyennes et recommande aux clients de mettre \u00e0 jour les mod\u00e8les BAS-IP concern\u00e9s avec la derni\u00e8re version du micrologiciel.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"risk-assessment\">\u00c9valuation des risques<\/h2>\n\n\n\n<p>Un adversaire potentiel a besoin d&rsquo;un acc\u00e8s r\u00e9seau \u00e0 l&rsquo;appareil pour exploiter les vuln\u00e9rabilit\u00e9s. Un adversaire a besoin d&rsquo;informations d&rsquo;identification pour r\u00e9ussir \u00e0 compromettre l&rsquo;appareil. Le risque d\u00e9pend du degr\u00e9 d&rsquo;exposition de l&rsquo;appareil. Les appareils orient\u00e9s vers l&rsquo;internet (par exemple, expos\u00e9s par le biais d&rsquo;un transfert de port du routeur) pr\u00e9sentent un risque \u00e9lev\u00e9. Les produits d\u00e9ploy\u00e9s sur un r\u00e9seau local prot\u00e9g\u00e9 pr\u00e9sentent un risque plus faible.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"risk-mitigation\">Att\u00e9nuation des risques<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Il est fortement recommand\u00e9 de mettre \u00e0 jour les mod\u00e8les concern\u00e9s avec le dernier micrologiciel.<\/li>\n\n\n\n<li>Il n&rsquo;est pas recommand\u00e9 d&rsquo;exposer les appareils directement \u00e0 l&rsquo;internet (transfert de port).<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"affected-models-and-patched-firmware\">Mod\u00e8les concern\u00e9s et firmware corrig\u00e9<\/h2>\n\n\n\n<p>Liste des mod\u00e8les concern\u00e9s :<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>AV-01D<\/li>\n\n\n\n<li>AV-01MD<\/li>\n\n\n\n<li>AV-01MFD<\/li>\n\n\n\n<li>AV-01ED<\/li>\n\n\n\n<li>AV-01KD<\/li>\n\n\n\n<li>AV-01BD<\/li>\n\n\n\n<li>AV-01KBD<\/li>\n\n\n\n<li>AV-02D<\/li>\n\n\n\n<li>AV-02IDE<\/li>\n\n\n\n<li>AV-02IDR<\/li>\n\n\n\n<li>AV-02IPD<\/li>\n\n\n\n<li>AV-02FDE<\/li>\n\n\n\n<li>AV-02FDR<\/li>\n\n\n\n<li>AV-03D<\/li>\n\n\n\n<li>AV-03BD<\/li>\n\n\n\n<li>AV-04AFD<\/li>\n\n\n\n<li>AV-04ASD<\/li>\n\n\n\n<li>AV-04FD<\/li>\n\n\n\n<li>AV-04SD<\/li>\n\n\n\n<li>AV-05FD<\/li>\n\n\n\n<li>AV-05SD<\/li>\n\n\n\n<li>AA-07BD<\/li>\n\n\n\n<li>AA-07BDI<\/li>\n\n\n\n<li>BA-04BD<\/li>\n\n\n\n<li>BA-04MD<\/li>\n\n\n\n<li>BA-08BD<\/li>\n\n\n\n<li>BA-08MD<\/li>\n\n\n\n<li>BA-12BD<\/li>\n\n\n\n<li>BA-12MD<\/li>\n\n\n\n<li>CR-02BD<\/li>\n<\/ul>\n\n\n\n<p>Version corrig\u00e9e du micrologiciel :<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>3.9.2<\/li>\n<\/ul>","protected":false},"excerpt":{"rendered":"<p>Vue d&rsquo;ensemble Un probl\u00e8me a \u00e9t\u00e9 d\u00e9couvert dans plusieurs dispositifs d&rsquo;interphone BAS-IP. En acc\u00e9dant \u00e0 l&rsquo;interface web ou \u00e0 l&rsquo;API de l&rsquo;appareil, un pirate peut obtenir les mots de passe du serveur RTSP et du compte SIP de l&rsquo;appareil. BAS-IP classe ces vuln\u00e9rabilit\u00e9s comme moyennes et recommande aux clients de mettre \u00e0 jour les mod\u00e8les [&hellip;]<\/p>","protected":false},"author":3,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"inline_featured_image":false,"footnotes":""},"class_list":["post-122075","page","type-page","status-publish","hentry"],"acf":[],"_links":{"self":[{"href":"https:\/\/bas-ip.com\/fr\/wp-json\/wp\/v2\/pages\/122075","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/bas-ip.com\/fr\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/bas-ip.com\/fr\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/bas-ip.com\/fr\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/bas-ip.com\/fr\/wp-json\/wp\/v2\/comments?post=122075"}],"version-history":[{"count":1,"href":"https:\/\/bas-ip.com\/fr\/wp-json\/wp\/v2\/pages\/122075\/revisions"}],"predecessor-version":[{"id":122076,"href":"https:\/\/bas-ip.com\/fr\/wp-json\/wp\/v2\/pages\/122075\/revisions\/122076"}],"wp:attachment":[{"href":"https:\/\/bas-ip.com\/fr\/wp-json\/wp\/v2\/media?parent=122075"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}