Security Advisory – December, 2024: Buffer Overflow Vulnerability in Neat Devices Running Microsoft Teams
Advisory ID: NEAT-SA-2024-12-19
Publication date: December 19, 2024
Last updated: January 21, 2025
Severity: Medium — CVSS v3.1 Base Score: 6.8
CVSS vector: AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE ID: CVE-2024-48806
Summary
A buffer overflow vulnerability was identified on Neat devices running Microsoft Teams. It allowed a local or physically present user to bypass security locks on device settings by entering an excessively long string into the password field.
Affected Products
| Product | Affected firmware version | Fixed version |
| Neat Pad | NFA1.20240924.0507 | 24.6.0 |
| Neat Bar | NFB1.20240924.0005 | 24.6.0 |
| Neat Board | NFC1.20240924.0005 | 24.6.0 |
| Neat Bar Pro | NFD1.20240924.0007 | 24.6.0 |
| Neat Bar Generation 2 | NFE1.20240924.0005 | 24.6.0 |
| Neat Frame | NFF1.20240924.0007 | 24.6.0 |
| Neat Board 50 | NFH1.20240924.0005 | 24.6.0 |
| Neat Center | NFL1.20240924.0008 | 24.6.0 |
| Neat Board Pro | NFK1.20240924.0005 | 24.6.0 |
Impact
Exploiting this vulnerability could allow unauthorized modification of system settings that are normally locked and protected, such as network proxy configuration or a factory reset. Exploitation could also cause a temporary crash of the device’s user interface, requiring a reboot to resolve.
Details
This issue is classified as CWE-120 (Buffer Copy without Checking Size of Input, also known as a classic buffer overflow). Exploitation requires local or physical access to the device’s password entry field; it is not remotely exploitable.
Remediation
This vulnerability was addressed in firmware release 24.6.0. Update affected devices to version 24.6.0 or later. Full release notes are available here.
Acknowledgements
This vulnerability was reported by Mindaugas Sukys.
References
Contact
Questions about this advisory can be directed to security@neat.no.