PT-2018-15290 · Sonicwall · Secure Access Sa Series Ssl Vpn
Rafael Pedrero
·
Publicado
2018-12-21
·
Atualizado
2019-10-03
·
CVE-2018-20193
CVSS v3.1
8.8
Alta
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Secure Access SA Series SSL VPN versions 4.2 through 5.1R5
Description
The issue allows for privilege escalation. This is demonstrated by the ability of a readonly user to change the administrator user password. The exploitation occurs because appropriate controls are not performed, allowing a readonly user to make a local copy of the /dana-admin/user/update.cgi page, change the
user value, and save the changes.Recommendations
For Secure Access SA Series SSL VPN versions 4.2 through 5.1R5, consider restricting access to the /dana-admin/user/update.cgi page to prevent unauthorized changes to the administrator user password. As a temporary workaround, restrict the ability of readonly users to modify the
user value in the update.cgi page until a patch is available.Exploit
Correção
Improper Privilege Management
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Secure Access Sa Series Ssl Vpn