PT-2018-15290 · Sonicwall · Secure Access Sa Series Ssl Vpn

Rafael Pedrero

·

Publicado

2018-12-21

·

Atualizado

2019-10-03

·

CVE-2018-20193

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Secure Access SA Series SSL VPN versions 4.2 through 5.1R5
Description The issue allows for privilege escalation. This is demonstrated by the ability of a readonly user to change the administrator user password. The exploitation occurs because appropriate controls are not performed, allowing a readonly user to make a local copy of the /dana-admin/user/update.cgi page, change the user value, and save the changes.
Recommendations For Secure Access SA Series SSL VPN versions 4.2 through 5.1R5, consider restricting access to the /dana-admin/user/update.cgi page to prevent unauthorized changes to the administrator user password. As a temporary workaround, restrict the ability of readonly users to modify the user value in the update.cgi page until a patch is available.

Exploit

Correção

Improper Privilege Management

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-20193

Produtos afetados

Secure Access Sa Series Ssl Vpn