CVE-2018-20219 Information

Description

An issue was discovered on Teracue ENC-400 devices with firmware 2.56 and below. After successful authentication the device sends an authentication cookie to the end user such that they can access the devices web administration panel. This token is hard-coded to a string in the source code (/usr/share/www/check.lp file). By setting this cookie in a browser an attacker is able to maintain access to every ENC-400 device without knowing the password which results in authentication bypass. Even if a user changes the password on the device this token is static and unchanged.

CVSS Vector

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Reference

https://zxsecurity.co.nz/research.html http://seclists.org/fulldisclosure/2019/Feb/48 http://packetstormsecurity.com/files/151802/Teracue-ENC-400-Command-Injection-Missing-Authentication.html

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction Required

NONE

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

HIGH

Availability Impact

HIGH

Base Score

HIGH

Base Severity

8.1

Share on: