CVE-2019-12775 Information
Description
An issue was discovered on the ENTTEC Datagate MK2 Storm 24 Pixelator and E-Streamer MK2 with firmware 70044_update_05032019-482. They allow high-privileged root access by www-data via sudo without requiring appropriate access control. (Furthermore the user account that controls the web application service is granted full access to run any system commands with elevated privilege without the need for password authentication. Should vulnerabilities be identified and exploited within the web application it may be possible for a threat actor to create or run high-privileged binaries or executables that are available within the operating system of the device.)
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Reference
https://www.mogozobo.com/?p=3476
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
8.8
Share on: