PT-2019-9888 · Adtran · Adtran Pmaa
Publicado
2019-03-27
·
Atualizado
2019-10-03
·
CVE-2018-19648
CVSS v2.0
9.0
Alta
| Vetor | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
ADTRAN PMAA versions 1.6.2-1 through 1.6.4
Description
An issue was discovered that allows unprivileged users to create privileged users and execute arbitrary commands. This is achieved through the use of the diagnostic-profile over RESTCONF, due to a flaw in NETCONF Access Management (NACM).
Recommendations
For ADTRAN PMAA versions 1.6.2-1 through 1.6.4, consider restricting access to the diagnostic-profile over RESTCONF until a patch is available. As a temporary workaround, limit the creation of new users and monitor user activity closely to prevent potential exploitation.
Correção
Improper Privilege Management
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Adtran Pmaa