PT-2019-15562 · Fastweb · Fastgate
Angeloanatrella86
·
Published
2019-11-02
·
Updated
2020-08-24
·
CVE-2019-18661
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Fastweb FASTGate version 1.0.1b
Description
The issue allows for partial authentication bypass by modifying a certain
check pwd return value from 0 to 1. Although an attack does not grant administrative control of a device, it enables the attacker to view all web pages of the administration console.Recommendations
For Fastweb FASTGate version 1.0.1b, consider modifying the
check pwd function to prevent return value manipulation until a patch is available. Restrict access to the administration console to minimize the risk of exploitation.Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fastgate