PT-2006-1990 · Thomson · Thomson Speedtouch

Publicado

2006-03-01

·

Atualizado

2011-03-08

·

CVE-2006-0947

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Thomson SpeedTouch modem version 5.3.2.6.0
Description The issue allows remote attackers to create users that cannot be deleted via scripting code in the 31 parameter in a NewUser function. This function is not filtered by the modem when creating the account, but the created users cannot be deleted by the administrator, possibly due to cleansing that occurs in the administrator interface.
Recommendations For Thomson SpeedTouch modem version 5.3.2.6.0, as a temporary workaround, consider restricting the use of the NewUser function until a patch is available. Additionally, avoid using the 31 parameter in the affected function to minimize the risk of exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-0947

Produtos afetados

Thomson Speedtouch