Security Advisory – December, 2024: Buffer Overflow Vulnerability in Neat Devices Running Microsoft Teams

Advisory ID: NEAT-SA-2024-12-19
Publication date: December 19, 2024
Last updated: January 21, 2025

Severity: Medium — CVSS v3.1 Base Score: 6.8
CVSS vector: AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE ID: CVE-2024-48806

Summary

A buffer overflow vulnerability was identified on Neat devices running Microsoft Teams. It allowed a local or physically present user to bypass security locks on device settings by entering an excessively long string into the password field.

Affected Products

ProductAffected firmware versionFixed version
Neat PadNFA1.20240924.050724.6.0
Neat BarNFB1.20240924.000524.6.0
Neat BoardNFC1.20240924.000524.6.0
Neat Bar ProNFD1.20240924.000724.6.0
Neat Bar Generation 2NFE1.20240924.000524.6.0
Neat FrameNFF1.20240924.000724.6.0
Neat Board 50NFH1.20240924.000524.6.0
Neat CenterNFL1.20240924.000824.6.0
Neat Board ProNFK1.20240924.000524.6.0

Impact

Exploiting this vulnerability could allow unauthorized modification of system settings that are normally locked and protected, such as network proxy configuration or a factory reset. Exploitation could also cause a temporary crash of the device’s user interface, requiring a reboot to resolve.

Details

This issue is classified as CWE-120 (Buffer Copy without Checking Size of Input, also known as a classic buffer overflow). Exploitation requires local or physical access to the device’s password entry field; it is not remotely exploitable.

Remediation

This vulnerability was addressed in firmware release 24.6.0. Update affected devices to version 24.6.0 or later. Full release notes are available here.

Acknowledgements

This vulnerability was reported by Mindaugas Sukys.

References

Contact

Questions about this advisory can be directed to security@neat.no.