CVE-2023-36669: Kratosdefense Ngc Indoor Unit Firmware
Critical severity, CVSS 9.8. EPSS: 0.9% chance of exploitation in the next 30 days.
Missing Authentication for a Critical Function within the Kratos NGC Indoor Unit (IDU) before 11.4 allows remote attackers to obtain arbitrary control of the IDU/ODU system. Any attacker with layer-3 network access to the IDU can impersonate the Touch Panel Unit (TPU) within the IDU by sending crafted TCP requests to the IDU.
Affected products
- Kratosdefense Ngc Indoor Unit Firmware: before 11.4 (fixed in 11.4)
Published 2023-07-18. Last modified 2026-06-17.