ID

VAR-201312-0499


TITLE

SAProuter Verification Bypass Vulnerability

Trust: 0.6

sources: CNVD: CNVD-2013-15064

DESCRIPTION

Saprouter is an SAP program that acts as a mediation station (agent) that connects the SAP system to the external network. SAProuter 39.3 SP4 (7100.0.0.201) - Win64/Linux x86_64, 40.4 applications fail to properly restrict access to certain features, allowing remote attackers to exploit the vulnerability to modify the configuration

Trust: 0.72

sources: CNVD: CNVD-2013-15064 // IVD: 9a983340-1ef8-11e6-abef-000c29c66e3d

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.8

sources: IVD: 9a983340-1ef8-11e6-abef-000c29c66e3d // CNVD: CNVD-2013-15064

AFFECTED PRODUCTS

vendor:sapmodel:saprouter sp4scope:eqversion:39.3(7100.0.0.201)

Trust: 0.6

vendor:sapmodel: - scope:eqversion:*

Trust: 0.2

vendor:saproutermodel:sp4scope:eqversion:39.3(7100.0.0.201)*

Trust: 0.2

sources: IVD: 9a983340-1ef8-11e6-abef-000c29c66e3d // CNVD: CNVD-2013-15064

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2013-15064
value: MEDIUM

Trust: 0.6

IVD: 9a983340-1ef8-11e6-abef-000c29c66e3d
value: MEDIUM

Trust: 0.2

CNVD: CNVD-2013-15064
severity: MEDIUM
baseScore: 6.6
vectorString: AV:N/AC:H/AU:N/C:P/I:C/A:P
accessVector: NETWORK
accessComplexity: HIGH
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: COMPLETE
availabilityImpact: PARTIAL
exploitabilityScore: 4.9
impactScore: 8.5
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

IVD: 9a983340-1ef8-11e6-abef-000c29c66e3d
severity: MEDIUM
baseScore: 6.6
vectorString: AV:N/AC:H/AU:N/C:P/I:C/A:P
accessVector: NETWORK
accessComplexity: HIGH
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: COMPLETE
availabilityImpact: PARTIAL
exploitabilityScore: 4.9
impactScore: 8.5
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.9 [IVD]

Trust: 0.2

sources: IVD: 9a983340-1ef8-11e6-abef-000c29c66e3d // CNVD: CNVD-2013-15064

TYPE

Access verification error

Trust: 0.2

sources: IVD: 9a983340-1ef8-11e6-abef-000c29c66e3d

PATCH

title:SAProuter verifies patches that bypass vulnerabilitiesurl:https://www.cnvd.org.cn/patchinfo/show/41613

Trust: 0.6

sources: CNVD: CNVD-2013-15064

EXTERNAL IDS

db:CNVDid:CNVD-2013-15064

Trust: 0.8

db:IVDid:9A983340-1EF8-11E6-ABEF-000C29C66E3D

Trust: 0.2

sources: IVD: 9a983340-1ef8-11e6-abef-000c29c66e3d // CNVD: CNVD-2013-15064

REFERENCES

url:http://erpscan.com/advisories/erpscan-13-023-saprouter-authentication-bypass/

Trust: 0.6

sources: CNVD: CNVD-2013-15064

SOURCES

db:IVDid:9a983340-1ef8-11e6-abef-000c29c66e3d
db:CNVDid:CNVD-2013-15064

LAST UPDATE DATE

2022-05-17T02:03:22.372000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2013-15064date:2013-12-16T00:00:00

SOURCES RELEASE DATE

db:IVDid:9a983340-1ef8-11e6-abef-000c29c66e3ddate:2013-12-16T00:00:00
db:CNVDid:CNVD-2013-15064date:2013-12-16T00:00:00