Security Advisory – January, 2023: Devices Running Microsoft Teams Rooms Allow for Remote Admin Password Change without Authentication

Advisory ID: NEAT-SA-2023-01-23
Publication date: January 23, 2023
Last updated: January 23, 2023

Severity: High
CVSS vector: Not applicable — not scored
CVE ID: Not applicable — no CVE was assigned

Summary

Neat Pad, Neat Bar, Neat Bar Pro, Neat Board, and Neat Frame running Microsoft Teams Rooms allowed the Remote Access administrator password to be changed without an authentication challenge. Because Neat devices use a single administrator password for managing configuration, changing the Remote Access admin password also changed the local Microsoft Teams admin account on the device.

Affected Products

ProductAffected firmware version
Neat PadNFA1.20220914.1215
Neat BarNFB1.20220914.1215
Neat BoardNFC1.20220914.1215
Neat Bar ProNFD1.20220914.1215
Neat FrameNFF1.20220914.1215

Fixed version: firmware release 20221128 or later (see Remediation).

Impact

An unauthenticated change to the administrator password could allow unauthorized configuration changes that were otherwise locked and protected, including Wi-Fi and Ethernet interface settings, proxy configuration, Bluetooth, and a factory reset of the device.

Details

This is a missing-authentication issue (CWE-306): the Remote Access password-change function did not require the requester to authenticate before changing the sole administrator credential, which also controls the local Microsoft Teams admin account on the device.

Remediation

This vulnerability was addressed in firmware release 20221128, which requires authentication before remote access configuration can be changed and streamlines the settings available to administrators. Full release notes are available here.

Workaround if firmware cannot be updated immediately: enable web remote access, then lock down the password from the device’s web admin page. Log in, select Access Settings in the lower-left corner, set a password, and enable Lock Remote Access Settings. Once enabled, the device’s local Remote Access screen no longer shows a password field and instead directs the user to sign in from the web browser to make changes.

Acknowledgements

Not applicable — identified through Neat’s internal security review.

References

Contact

Questions about this advisory can be directed to security@neat.no.