PT-2018-12228 · Trivum · Trivum Webtouch Setup V9
Vulnc0D3
·
Publicado
2018-07-17
·
Atualizado
2019-10-03
·
CVE-2018-13861
CVSS v2.0
10
Crítica
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Trivum WebTouch Setup V9 version 2.53 build 13163
Description
The issue allows unauthorized remote attackers to reboot or execute other functions. This can be achieved by accessing the "/xml/system/control.xml" URL using a GET request with parameters such as "?action=reboot".
Recommendations
For Trivum WebTouch Setup V9 version 2.53 build 13163, as a temporary workaround, consider restricting access to the "/xml/system/control.xml" URL to minimize the risk of exploitation. Avoid using the
action parameter in the affected URL until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability. Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Trivum Webtouch Setup V9