CyberRota Analysis
AI-GeneratedThe AJA HELO Plus firmware versions prior to 2.1.7 are vulnerable to an information disclosure flaw that allows unauthenticated attackers to decrypt sensitive diagnostics bundles due to a static AES passphrase embedded in the firmware. By reverse engineering the firmware, attackers can recover this passphrase and access sensitive server information from the unauthenticated diagnostics endpoint. Organizations using affected devices should prioritize patching to mitigate the risk of exposing critical data.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
AJA HELO Plus firmware before 2.1.7 contains an information disclosure vulnerability that allows unauthenticated attackers to decrypt sensitive diagnostics bundles by exploiting a static AES passphrase embedded in obfuscated form within the firmware. Attackers can reverse engineer the publicly available firmware image to recover the shared passphrase and decrypt diagnostics export bundles retrieved from the unauthenticated diagnostics endpoint on any affected device, exposing highly sensitive server information.