PT-2019-13149 · Inteno · Inteno Eg200

Gerard Fuguet

·

Publicado

2019-09-16

·

Atualizado

2022-03-31

·

CVE-2019-13140

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Inteno EG200 EG200-WU7P1U ADAMO version 3.16.4-190226 1650
Description The issue is related to a JUCI ACL misconfiguration. This misconfiguration allows the user account to extract the 3DES key via JSON commands to ubus. The 3DES key is used for decrypting the provisioning file, which is provided by Adamo Telecom on a public URL via cleartext HTTP.
Recommendations For Inteno EG200 EG200-WU7P1U ADAMO version 3.16.4-190226 1650, as a temporary workaround, consider restricting access to the ubus JSON commands to prevent the extraction of the 3DES key. Additionally, avoid using cleartext HTTP for provisioning files. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Correção

Files Accessible to External Parties

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-13140

Produtos afetados

Inteno Eg200