PT-2020-16914 · Amodat · Jamodat Tsmmanager Collector
Voidsec
·
Published
2020-11-19
·
Updated
2021-07-21
·
CVE-2020-28054
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
JamoDat TSMManager Collector version up to 6.5.0.21
Description
The issue is related to an Authorization Bypass in the Collector component, which does not properly validate an authenticated session with the Viewer. If the Viewer has been modified and the Bypass Login functionality is used, an attacker can access various Collector functionalities as if they were a properly logged-in user. This includes administrating connected instances, reviewing logs, editing configurations, accessing instances' consoles, and accessing hardware configurations. However, exploiting this issue will not grant an attacker access or control over remote ISP servers, as no credentials are sent with the request.
Recommendations
For JamoDat TSMManager Collector version up to 6.5.0.21, consider disabling the Bypass Login functionality in the Viewer to prevent unauthorized access until a patch is available. Restrict access to the Collector component to minimize the risk of exploitation. Avoid using modified or binary-patched Viewer versions to prevent potential bypassing of authentication mechanisms. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Jamodat Tsmmanager Collector