Security Advisory – April, 2024: Vulnerability in NeatOS and Pulse Agent Could Affect Content Sharing 

Advisory ID: NEAT-SA-2024-04-24
Publication date: April 24, 2024 
Last updated: April 24, 2024

Severity: Low
CVSS vector: Not applicable
CVE ID: Not applicable — no CVE was assigned

Summary

A vulnerability was identified affecting Neat devices running NeatOS 24.1.0 to 24.2.0 with Pulse Agent 0.8.43 or 0.9.24. A threat actor with local area network access could conceivably cause a Neat device that is pre-configured to automatically share content over HDMI to display content from an unauthenticated source. The same condition could also cause a device to display a black screen during a network port scan.

Affected Products

ProductAffected versionsFixed version
Neat devices with Pulse Agent 0.8.43 or 0.9.24NeatOS 24.1.0 – 24.2.0Pulse Agent 0.9.25 or later

Impact

Neat assessed the likelihood of exploitation as extremely low, describing it as a theoretical possibility requiring local network access and a specific auto-share configuration. A related condition could cause a temporary black screen during a network port scan.

Details

Identified internally by Neat’s security and development teams during ongoing security assessment of NeatOS and the Pulse Agent.

Remediation

Update the Neat Pulse Agent to version 0.9.25 or later. Neat released this version on April 22, 2024; devices configured for automatic updates should already be running it.

Acknowledgements

Not applicable — identified internally by Neat’s security and development teams.

References

Contact

Questions about this advisory can be directed to security@neat.no.