PT-2018-6585 · Openwrt+1 · Openwrt+2
Neonsea
·
Publicado
2018-01-04
·
Atualizado
2019-10-03
·
CVE-2017-17867
CVSS v2.0
9.0
Alta
| Vetor | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Inteno iopsys versions 2.0 through 3.14
Inteno iopsys version 4.0
Description:
The issue allows remote authenticated users to execute arbitrary OS commands by modifying the
leasetrigger field in the odhcpd configuration. This can be done to specify an arbitrary program, such as one located on an SMB share. The problem exists due to the improper use of the /etc/uci-defaults directory, which fails to secure the OpenWrt configuration.Recommendations:
For Inteno iopsys versions 2.0 through 3.14, update the configuration to properly utilize the /etc/uci-defaults directory for securing OpenWrt.
For Inteno iopsys version 4.0, update the configuration to properly utilize the /etc/uci-defaults directory for securing OpenWrt.
As a temporary workaround, consider restricting access to the odhcpd configuration to minimize the risk of exploitation.
Exploit
Correção
Incorrect Permission
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Inteno Iopsys
Openwrt
Odhcpd