PT-2019-8654 · Vera+1 · Vera Veralite+1

Mandar Satam

·

Published

2019-06-17

·

Updated

2019-06-20

·

CVE-2017-9385

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Vera Veralite version 1.7.481
Description An issue was discovered on the device, which has an additional OpenWRT interface in addition to the standard web interface, allowing the highest privileges a user can obtain on the device. This web interface uses root as the username and the password in the /etc/cmh/cmh.conf file, which can be extracted by an attacker using a directory traversal attack, and then log in to the device with the highest privileges.
Recommendations For Vera Veralite version 1.7.481, consider disabling the OpenWRT interface as a temporary workaround until a patch is available. Restrict access to the /etc/cmh/cmh.conf file to minimize the risk of exploitation. Avoid using the root username in the affected web interface until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-9385

Affected Products

Openwrt
Vera Veralite