News from 2023-08-16


Meinberg Security Advisory: [MBGSA-2023.04] LANTIME-Firmware V7.08.002


The LANTIME firmware version 7.08.002 includes security updates of various third party libraries and programs. In addition this update fixes further in this Advisory listed vulnerabilities of the LANTIME OS.

Meinberg recommends updating to LANTIME firmware version 7.08.002.

Estimation of Severity up to and including
  • LANTIME firmware V7.08.001:
    severity level critical(0), high (2), medium (4), low (6), unknown (0)
  • LANTIME firmware V7.06.014:
    severity level critical(0), high (2), medium (4), low (6), unknown (0)
Updated Version:
  • LANTIME firmware: V7.08.002
  1. Description of the Vulnerabilities

    • Third-party software:
    • Web-Interface and System:
      • NOCVE - JavaScript Code Injection / XSS in Log File (low)

        Super-User were able to include JavaScript code in the Log-file “lantime_messages“ that would be delivered via web interface.

        Fixed in:
        V7.08.002 MBGID-14449

      • NOCVE - Signatur Bypass (high)

        The signature check of uploaded firmware image files could be bypassed because of performing it too late. The check is now performed as early as possible.

        Fixed in:
        V7.08.002 MBGID-14459

      • NOCVE - Persisted hidden user can be created (low)

        User with a name that consisted of parts of a system username were not displayed in the web interface.

        Fixed in:
        V7.08.002 MBGID-14448

  2. Systems Affected

    All LANTIME firmware versions before V7.08.002 are affected by the corresponding vulnerabilities. The LANTIME firmware is used by all devices of the LANTIME M series (M100, M150, M200, M250, M300, M320, M400, M450, M600, M900) as well as all devices of the LANTIME IMS series (M500, M1000, M1000S, M2000S, M3000, M3000S, M4000) and the SyncFire product family (SF1000, SF1100, SF1200, SF1500).

    Whether and to what extent individual clients or LANTIME systems are vulnerable depends on the individual configuration, network infrastructure, and other factors, and it is therefore not possible to provide a general statement on how vulnerable a given system in use actually is.

  3. Possible Security Measures

    The relevant security updates are included in the LANTIME firmware versions V7.08.002(-light). Updating to these versions eliminates the listed vulnerabilities.

    Download the latest LANTIME firmware at:

    All updates are now available for Meinberg customers. An update of the LANTIME firmware to the version 7.08.002 respectively 7.08.002-light is recommended. Clients who cannot install version 7.08.002 should install V7.08.002-light instead.

  4. Further Information

    Further details and information are available from the following websites:

    If you have any questions or need assistance, please, do not hesitate to contact Meinberg’s technical support team.

  5. Acknowledgments

    We would like to express our gratitude to all those who have advised us of vulnerabilities or other bugs, and have also suggested improvements to us.

    Thank you!


Meinberg Mail Contact Meinberg Mail Contact Meinberg Mail Contact Meinberg Mail Contact Meinberg Mail Contact Meinberg Mail Contact Meinberg Mail Contact Meinberg Mail Contact Meinberg Mail Contact Meinberg Mail Contact Meinberg Mail Contact Meinberg Mail Contact Meinberg Mail Contact Meinberg Mail Contact Meinberg Mail Contact Meinberg Mail Contact Meinberg Mail Contact Meinberg Mail Contact Meinberg Mail Contact Meinberg Mail Contact Meinberg Mail Contact Meinberg Mail Contact Meinberg Mail Contact Meinberg Mail Contact Meinberg Mail Contact Meinberg Mail Contact