PT-2018-13694 · Furuno · Furuno Felcom

Cyberskr

·

Publicado

2018-09-10

·

Atualizado

2019-10-03

·

CVE-2018-16705

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions FURUNO FELCOM versions 250 and 500
Description The issue allows unauthenticated access to the xml/permission.xml file, which contains system usernames and passwords, including Admin and Service user accounts with unsalted MD5 hashes, and the SMS server password in cleartext.
Recommendations For FURUNO FELCOM versions 250 and 500, restrict access to the xml/permission.xml file to prevent unauthorized access to sensitive system information. As a temporary workaround, consider disabling unauthenticated access to the device until a patch is available. Avoid using the device's default passwords and consider changing them to stronger, unique passwords.

Exploit

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-16705

Produtos afetados

Furuno Felcom