PT-2019-13149 · Inteno · Inteno Eg200
Gerard Fuguet
·
Publicado
2019-09-16
·
Atualizado
2022-03-31
·
CVE-2019-13140
CVSS v3.1
6.5
Média
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Inteno EG200 EG200-WU7P1U ADAMO version 3.16.4-190226 1650
Description
The issue is related to a JUCI ACL misconfiguration. This misconfiguration allows the
user account to extract the 3DES key via JSON commands to ubus. The 3DES key is used for decrypting the provisioning file, which is provided by Adamo Telecom on a public URL via cleartext HTTP.Recommendations
For Inteno EG200 EG200-WU7P1U ADAMO version 3.16.4-190226 1650, as a temporary workaround, consider restricting access to the
ubus JSON commands to prevent the extraction of the 3DES key. Additionally, avoid using cleartext HTTP for provisioning files. At the moment, there is no information about a newer version that contains a fix for this issue.Exploit
Correção
Files Accessible to External Parties
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Inteno Eg200