Security Advisory – March, 2026: Low-Risk ICMP Information Disclosure on Neat Board 50 and Neat Board Pro

Advisory ID: NEAT-SA-2025-03-21-2
Publication date: March 21, 2026
Last updated: March 21, 2026

Severity: Low — CVSS v2.0 Base Score: 2.1 (as identified for CVE-1999-0524). CISA-ADP’s CVSS v3.1 re-scoring of the same underlying issue class is 4.0 (Medium).

CVSS vector: CVSS v2.0: (AV:L/AC:L/Au:N/C:P/I:N/A:N)  |  CVSS v3.1 (CISA-ADP): AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CVE ID: CVE-1999-0524

Summary

Neat addressed a low-risk information disclosure issue on Neat Board 50 and Neat Board Pro related to how the devices responded to ICMP netmask and timestamp requests. Devices running affected firmware would respond to these ICMP requests from arbitrary hosts on the local network, which can reveal minor system information such as the device’s subnet mask or system clock value. This corresponds to the long-documented vulnerability class tracked as CVE-1999-0524 (CWE-200: Exposure of Sensitive Information to an Unauthorized Actor).

Affected Products

ProductAffected versionsFixed version
Neat Board 50NeatOS 25.4.2 and earlier (Stable channel)NeatOS 25.4.2
Neat Board ProNeatOS 25.4.2 and earlier (Stable channel)NeatOS 25.4.2

Impact

Low. An attacker on the same local network as an affected device could send unauthenticated ICMP netmask or timestamp requests and receive a response containing the device’s subnet mask or system clock time. This does not expose credentials, meeting content, or configuration data, and does not allow modification of the device or unauthorized access.

Details

This is a long-recognized, low-severity class of issue affecting many IP-stack implementations that respond to ICMP Address Mask Request and Timestamp Request messages without restriction. It is commonly flagged by network vulnerability scanners during routine security assessments. Neat’s fix restricts or disables these ICMP responses on Neat Board 50 and Neat Board Pro.

Remediation

Update to NeatOS 25.4.2. No workaround is required given the low severity; network-level ICMP filtering can also mitigate this at the customer’s discretion prior to updating.

Acknowledgements

Not specified in the original release notes. Confirm with engineering whether this was identified internally or reported by an external party (e.g., during a customer or third-party penetration test) before publishing, since a reporter may be owed credit.

References

Contact

Questions about this advisory can be directed to security@neat.no.