PT-2020-16914 · Amodat · Jamodat Tsmmanager Collector

Voidsec

·

Published

2020-11-19

·

Updated

2021-07-21

·

CVE-2020-28054

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions JamoDat TSMManager Collector version up to 6.5.0.21
Description The issue is related to an Authorization Bypass in the Collector component, which does not properly validate an authenticated session with the Viewer. If the Viewer has been modified and the Bypass Login functionality is used, an attacker can access various Collector functionalities as if they were a properly logged-in user. This includes administrating connected instances, reviewing logs, editing configurations, accessing instances' consoles, and accessing hardware configurations. However, exploiting this issue will not grant an attacker access or control over remote ISP servers, as no credentials are sent with the request.
Recommendations For JamoDat TSMManager Collector version up to 6.5.0.21, consider disabling the Bypass Login functionality in the Viewer to prevent unauthorized access until a patch is available. Restrict access to the Collector component to minimize the risk of exploitation. Avoid using modified or binary-patched Viewer versions to prevent potential bypassing of authentication mechanisms. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2020-28054

Affected Products

Jamodat Tsmmanager Collector