PT-2022-27642 · Hillstone · Hillstone Firewall Sg-6000
Yinfei6
·
Published
2022-12-27
·
Updated
2023-08-08
·
CVE-2022-45778
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Hillstone Firewall SG-6000 versions 5.0.4.0 and earlier
Description
The issue is related to incorrect access control, allowing an attacker to bypass permissions and gain super administrator privileges in the background of the firewall. This is due to a configuration error in the report module.
Recommendations
For Hillstone Firewall SG-6000 versions 5.0.4.0 and earlier, update to a version later than 5.0.4.0 to resolve the issue. As a temporary workaround, consider restricting access to the report module to minimize the risk of exploitation.
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hillstone Firewall Sg-6000