PT-2019-8654 · Vera+1 · Vera Veralite+1
Mandar Satam
·
Published
2019-06-17
·
Updated
2019-06-20
·
CVE-2017-9385
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Vera Veralite version 1.7.481
Description
An issue was discovered on the device, which has an additional OpenWRT interface in addition to the standard web interface, allowing the highest privileges a user can obtain on the device. This web interface uses
root as the username and the password in the /etc/cmh/cmh.conf file, which can be extracted by an attacker using a directory traversal attack, and then log in to the device with the highest privileges.Recommendations
For Vera Veralite version 1.7.481, consider disabling the OpenWRT interface as a temporary workaround until a patch is available. Restrict access to the
/etc/cmh/cmh.conf file to minimize the risk of exploitation. Avoid using the root username in the affected web interface until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openwrt
Vera Veralite