Executive brief
ATEN Unizon, a centralized management software for AV and power distribution systems, is vulnerable to a flaw that allows an unauthorized person to crash the service. By sending specific requests to the system's communication interface, an attacker can disrupt operations and make the management console unavailable to legitimate users. This could lead to a loss of control over connected hardware and operational downtime.
Technical details
A denial-of-service vulnerability exists in the RpcProvider class of ATEN Unizon due to missing authentication for critical functions (CWE-306). The software fails to verify the identity of a user before granting access to certain RPC functionality. A remote, unauthenticated attacker can exploit this by sending crafted requests to the RpcProvider interface, leading to a service crash or exhaustion of resources. The vulnerability was reported via ZDI-CAN-29041 and affects version 2.6.253.001. ATEN has released an update to address this issue.
Affected products
- ATEN Unizon 2.6.253.001
Timeline
- 2026-01-30: disclosed: Vulnerability reported to vendor
- 2026-04-15: patched: Coordinated public release of advisory and vendor update
- 2026-07-29: advisory: NVD publication date