PT-2017-18718 · Mimosa · Mimosa Client Radios

Publicado

2017-05-21

·

Atualizado

2019-10-03

·

CVE-2017-9136

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Mimosa Client Radios versions prior to 2.2.3
Description An issue in the device's web interface allows an attacker to download files from the device as the root user by using an unsanitized GET parameter. This can be used to view unsalted, MD5-hashed administrator passwords, which can then be cracked to give the attacker full admin access to the device's web interface. The attacker can also view the plaintext pre-shared key (PSK) for encrypted wireless connections or the device's serial number, allowing for a factory reset.
Recommendations For versions prior to 2.2.3, update to version 2.2.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the device's web interface to minimize the risk of exploitation. Avoid using the vulnerable web interface until the issue is resolved.

Correção

Insufficiently Protected Credentials

Incorrect Permission

Use of a Broken Cryptographic Algorithm

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-9136

Produtos afetados

Mimosa Client Radios