PT-2018-3327 · Wifiranger · Wifiranger

Publicado

2018-10-19

·

Atualizado

2020-08-24

·

CVE-2018-17873

CVSS v3.1

8.8

Alta

VetorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: WiFiRanger versions 7.0.8rc3 and earlier
Description: The issue is related to an incorrect access control vulnerability in the FTP configuration, which can be exploited by an attacker with adjacent network access to read the SSH Private Key and log in to the root account. This vulnerability is also associated with errors in key management, potentially allowing a remote attacker to gain access to the SSH key and enter the system with a root account.
Recommendations: For WiFiRanger versions 7.0.8rc3 and earlier, consider restricting access to the FTP configuration and SSH Private Key to minimize the risk of exploitation. As a temporary workaround, restrict access to the root account until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Incorrect Permission

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2019-04820
CVE-2018-17873

Produtos afetados

Wifiranger