PT-2019-15562 · Fastweb · Fastgate

Angeloanatrella86

·

Published

2019-11-02

·

Updated

2020-08-24

·

CVE-2019-18661

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Fastweb FASTGate version 1.0.1b
Description The issue allows for partial authentication bypass by modifying a certain check pwd return value from 0 to 1. Although an attack does not grant administrative control of a device, it enables the attacker to view all web pages of the administration console.
Recommendations For Fastweb FASTGate version 1.0.1b, consider modifying the check pwd function to prevent return value manipulation until a patch is available. Restrict access to the administration console to minimize the risk of exploitation.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-18661

Affected Products

Fastgate