PT-2019-8654 · Vera+1 · Vera Veralite+1
Mandar Satam
·
Publicado
2019-06-17
·
Atualizado
2019-06-20
·
CVE-2017-9385
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Vera Veralite version 1.7.481
Description
An issue was discovered on the device, which has an additional OpenWRT interface in addition to the standard web interface, allowing the highest privileges a user can obtain on the device. This web interface uses
root as the username and the password in the /etc/cmh/cmh.conf file, which can be extracted by an attacker using a directory traversal attack, and then log in to the device with the highest privileges.Recommendations
For Vera Veralite version 1.7.481, consider disabling the OpenWRT interface as a temporary workaround until a patch is available. Restrict access to the
/etc/cmh/cmh.conf file to minimize the risk of exploitation. Avoid using the root username in the affected web interface until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Openwrt
Vera Veralite