Horizon Alert
Summary of the vulnerability and why it matters
The DMS+ (Non-Mobile) system, developed by Rich Source, contains a critical vulnerability due to hard-coded credentials. This flaw allows unauthenticated attackers to leverage a fixed API key to potentially gain complete control over all installed DMS+ devices.
- Fixed key grants full device control.
- Impacts device management systems.
- Confirm relevance and exposure.
Attack Path
How an attacker could exploit the issue
An attacker can exploit a hard-coded API key within the DMS+ system. This allows unauthenticated remote access to a critical management API, enabling unauthorized control over all connected DMS+ devices.
- Unauthenticated network access is required.
- A fixed API key can be used.
- Full device control is the risk.
Live Threat
Current exploitation, exposure, and threat context
Unauthenticated remote attackers could exploit a fixed API key in DMS+ to gain control over installed devices. This could affect all installed DMS+ devices when they are accessible remotely.
- Device control over all DMS+ devices.
- Exploiting a fixed API key remotely.
- Complete loss of device security.
Operational Fix
Recommended remediation, mitigation, and detection steps
Addressing this critical vulnerability in DMS+ requires immediate action from teams responsible for device management and security. The first practical step is to inventory all DMS+ installations, assess their network exposure and business criticality, and identify the specific accountable owners for each instance. Once identified, a risk-based remediation plan can be developed, coordinating with the vendor as necessary.
- Device management and security teams own the issue.
- Verify DMS+ installations and network exposure first.
- Plan remediation with vendor coordination.