PT-2020-20401 · Timetools · Timetools Sr9210+9
Published
2020-02-13
·
Updated
2020-02-25
·
CVE-2020-8964
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
TimeTools SC7105 version 1.0.007
TimeTools SC9205 version 1.0.007
TimeTools SC9705 version 1.0.007
TimeTools SR7110 version 1.0.007
TimeTools SR9210 version 1.0.007
TimeTools SR9750 version 1.0.007
TimeTools SR9850 version 1.0.007
TimeTools T100 version 1.0.003
TimeTools T300 version 1.0.003
TimeTools T550 version 1.0.003
Description
The issue allows remote attackers to bypass authentication by placing
t3axs=TiMEtOOlsj7G3xMm52wB in a "t3.cgi" request. This is due to a hardcoded cookie.Recommendations
For TimeTools SC7105 version 1.0.007, consider disabling the
t3.cgi request until a patch is available.
For TimeTools SC9205 version 1.0.007, consider disabling the t3.cgi request until a patch is available.
For TimeTools SC9705 version 1.0.007, consider disabling the t3.cgi request until a patch is available.
For TimeTools SR7110 version 1.0.007, consider disabling the t3.cgi request until a patch is available.
For TimeTools SR9210 version 1.0.007, consider disabling the t3.cgi request until a patch is available.
For TimeTools SR9750 version 1.0.007, consider disabling the t3.cgi request until a patch is available.
For TimeTools SR9850 version 1.0.007, consider disabling the t3.cgi request until a patch is available.
For TimeTools T100 version 1.0.003, consider disabling the t3.cgi request until a patch is available.
For TimeTools T300 version 1.0.003, consider disabling the t3.cgi request until a patch is available.
For TimeTools T550 version 1.0.003, consider disabling the t3.cgi request until a patch is available.Exploit
Fix
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Timetools Sc7105
Timetools Sc9205
Timetools Sc9705
Timetools Sr7110
Timetools Sr9210
Timetools Sr9750
Timetools Sr9850
Timetools T100
Timetools T300
Timetools T550