PT-2019-6601 · Integard · Integard Home+1
Corelanc0D3R
+5
·
Published
2019-09-13
·
Updated
2024-02-14
·
CVE-2010-5333
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Integard Pro versions prior to 2.0.0.9037
Integard Home versions prior to 2.0.0.9037
Integard Pro and Home versions 2.2.x prior to 2.2.0.9037
Description
The web server has a buffer overflow via a long password in an administration login POST request, leading to arbitrary code execution. This issue can be exploited through an EIP-overwrite buffer overflow.
Recommendations
For Integard Pro and Home versions prior to 2.0.0.9037, update to version 2.0.0.9037 or later.
For Integard Pro and Home versions 2.2.x prior to 2.2.0.9037, update to version 2.2.0.9037 or later.
As a temporary workaround, consider restricting access to the administration login
POST request until a patch is available. Avoid using long passwords in the administration login until the issue is resolved.Exploit
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Integard Home
Integard Pro