PT-2018-11186 · Intelbras · Intelbras Nplug
Patrick Costa
+1
·
Publicado
2018-10-10
·
Atualizado
2018-11-28
·
CVE-2018-12455
CVSS v2.0
9.3
Alta
| Vetor | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Intelbras NPLUG version 1.0.0.14
Description
The issue allows an attacker to authenticate in the web interface by using "admin:" as the name of a cookie. This means that an attacker can potentially gain access to the device without needing a valid password.
Recommendations
For Intelbras NPLUG version 1.0.0.14, consider disabling the web interface until a patch is available to prevent potential exploitation. Restrict access to the device to minimize the risk of unauthorized access.
Exploit
Correção
Improper Authentication
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Intelbras Nplug