Security Advisory – April, 2024: Vulnerability in NeatOS and Pulse Agent Could Affect Content Sharing
Advisory ID: NEAT-SA-2024-04-24
Publication date: April 24, 2024
Last updated: April 24, 2024
Severity: Low
CVSS vector: Not applicable
CVE ID: Not applicable — no CVE was assigned
Summary
A vulnerability was identified affecting Neat devices running NeatOS 24.1.0 to 24.2.0 with Pulse Agent 0.8.43 or 0.9.24. A threat actor with local area network access could conceivably cause a Neat device that is pre-configured to automatically share content over HDMI to display content from an unauthenticated source. The same condition could also cause a device to display a black screen during a network port scan.
Affected Products
| Product | Affected versions | Fixed version |
| Neat devices with Pulse Agent 0.8.43 or 0.9.24 | NeatOS 24.1.0 – 24.2.0 | Pulse Agent 0.9.25 or later |
Impact
Neat assessed the likelihood of exploitation as extremely low, describing it as a theoretical possibility requiring local network access and a specific auto-share configuration. A related condition could cause a temporary black screen during a network port scan.
Details
Identified internally by Neat’s security and development teams during ongoing security assessment of NeatOS and the Pulse Agent.
Remediation
Update the Neat Pulse Agent to version 0.9.25 or later. Neat released this version on April 22, 2024; devices configured for automatic updates should already be running it.
Acknowledgements
Not applicable — identified internally by Neat’s security and development teams.
References
Contact
Questions about this advisory can be directed to security@neat.no.