Security Advisory – January, 2023: Devices Running Microsoft Teams Rooms Allow for Remote Admin Password Change without Authentication
Advisory ID: NEAT-SA-2023-01-23
Publication date: January 23, 2023
Last updated: January 23, 2023
Severity: High
CVSS vector: Not applicable — not scored
CVE ID: Not applicable — no CVE was assigned
Summary
Neat Pad, Neat Bar, Neat Bar Pro, Neat Board, and Neat Frame running Microsoft Teams Rooms allowed the Remote Access administrator password to be changed without an authentication challenge. Because Neat devices use a single administrator password for managing configuration, changing the Remote Access admin password also changed the local Microsoft Teams admin account on the device.
Affected Products
| Product | Affected firmware version |
| Neat Pad | NFA1.20220914.1215 |
| Neat Bar | NFB1.20220914.1215 |
| Neat Board | NFC1.20220914.1215 |
| Neat Bar Pro | NFD1.20220914.1215 |
| Neat Frame | NFF1.20220914.1215 |
Fixed version: firmware release 20221128 or later (see Remediation).
Impact
An unauthenticated change to the administrator password could allow unauthorized configuration changes that were otherwise locked and protected, including Wi-Fi and Ethernet interface settings, proxy configuration, Bluetooth, and a factory reset of the device.
Details
This is a missing-authentication issue (CWE-306): the Remote Access password-change function did not require the requester to authenticate before changing the sole administrator credential, which also controls the local Microsoft Teams admin account on the device.
Remediation
This vulnerability was addressed in firmware release 20221128, which requires authentication before remote access configuration can be changed and streamlines the settings available to administrators. Full release notes are available here.
Workaround if firmware cannot be updated immediately: enable web remote access, then lock down the password from the device’s web admin page. Log in, select Access Settings in the lower-left corner, set a password, and enable Lock Remote Access Settings. Once enabled, the device’s local Remote Access screen no longer shows a password field and instead directs the user to sign in from the web browser to make changes.
Acknowledgements
Not applicable — identified through Neat’s internal security review.
References
Contact
Questions about this advisory can be directed to security@neat.no.