PT-2022-12125 · Lanner · Iac-Ast2500A
Andrea Palanca
·
Published
2022-10-24
·
Updated
2024-09-30
·
CVE-2021-44467
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Lanner Inc IAC-AST2500A standard firmware version 1.10.0
Description
A broken access control vulnerability in the KillDupUsr func function of spx restservice allows an attacker to arbitrarily terminate active sessions of other users, causing a Denial-of-Service (DoS) condition, if an input parameter is correctly guessed.
Recommendations
For Lanner Inc IAC-AST2500A standard firmware version 1.10.0, as a temporary workaround, consider disabling the KillDupUsr func function until a patch is available. Restrict access to the spx restservice to minimize the risk of exploitation. Avoid using the vulnerable input parameter in the affected function until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Iac-Ast2500A