ID

VAR-201505-0339


CVE

CVE-2015-1188


TITLE

Swisscom Centro Grande DSL Router firmware HNDS Vulnerability to access the management function in the certificate verification function of the service

Trust: 0.8

sources: JVNDB: JVNDB-2015-002767

DESCRIPTION

The certificate verification functions in the HNDS service in Swisscom Centro Grande (ADB) DSL routers with firmware before 6.14.00 allows remote attackers to access the management functions via unknown vectors. The Swisscom Centro Grande DSL Router is a router device. Swisscom Centro Grande is prone to a remote authentication-bypass vulnerability. Product ------- Firmwares up to version 6.12.02 are affected. Furthermore, this vulnerability combined with other vulnerabilities allow to completely compromise the Centro Grande (ADB) routers. Available Proof-of-Concept code enables a remote root shell on a victim's router. Remediation ----------- Update the firmware to version 6.14.00. The current version can be verified through the web management interface, under Settings => Router => Firmware section. The version 6.14.00 should be installed. If it is not the case, the update can be forced cliking on the button labeled "Check for upgrade". Alternatively, the firmware can be downloaded from the following page: https://www.swisscom.ch/en/residential/help/device/internet-router/centro-grande.html Swisscom customers may call the Swisscom-Hotline 0800 800 800 Acknowledgments --------------- Ivan Almuina from Hacking Corporation S\xe0rl (http://hackingcorp.ch/) for the discovery, the notification and for helping us to fix the vulnerability. Milestones ---------- Sep 23th 2014 Vulnerability reported to Swisscom CSIRT Jan 7th 2015 CVE ID requested at MITRE Jan 18th 2015 CVE ID 2015-1188 assigned by MITRE Apr 29th 2015 Public Release of Advisory

Trust: 2.61

sources: NVD: CVE-2015-1188 // JVNDB: JVNDB-2015-002767 // CNVD: CNVD-2015-02889 // BID: 74391 // VULHUB: VHN-79149 // PACKETSTORM: 131672

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2015-02889

AFFECTED PRODUCTS

vendor:swisscommodel:centro grandescope:ltversion:6.14.00

Trust: 1.0

vendor:swisscommodel:centro grande dslscope: - version: -

Trust: 0.8

vendor:swisscommodel:centro grande dslscope:ltversion:6.14.00

Trust: 0.8

vendor:swisscommodel:centro grande dsl routerscope: - version: -

Trust: 0.6

vendor:swisscommodel:ag centro grandescope:eqversion:6.12.02

Trust: 0.3

vendor:swisscommodel:ag centro grandescope:neversion:6.14.00

Trust: 0.3

sources: CNVD: CNVD-2015-02889 // BID: 74391 // JVNDB: JVNDB-2015-002767 // NVD: CVE-2015-1188

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2015-1188
value: HIGH

Trust: 1.0

NVD: CVE-2015-1188
value: HIGH

Trust: 0.8

CNVD: CNVD-2015-02889
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-201505-335
value: CRITICAL

Trust: 0.6

VULHUB: VHN-79149
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2015-1188
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

NVD: CVE-2015-1188
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: NONE
impactScore: NONE
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.8

CNVD: CNVD-2015-02889
severity: MEDIUM
baseScore: 6.8
vectorString: AV:N/AC:M/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 8.6
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

VULHUB: VHN-79149
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: CNVD: CNVD-2015-02889 // VULHUB: VHN-79149 // JVNDB: JVNDB-2015-002767 // CNNVD: CNNVD-201505-335 // NVD: CVE-2015-1188

PROBLEMTYPE DATA

problemtype:NVD-CWE-Other

Trust: 1.0

problemtype:CWE-264

Trust: 0.9

sources: VULHUB: VHN-79149 // JVNDB: JVNDB-2015-002767 // NVD: CVE-2015-1188

THREAT TYPE

remote

Trust: 0.7

sources: PACKETSTORM: 131672 // CNNVD: CNNVD-201505-335

TYPE

other

Trust: 0.6

sources: CNNVD: CNNVD-201505-335

CONFIGURATIONS

sources: JVNDB: JVNDB-2015-002767

EXPLOIT AVAILABILITY

sources: VULHUB: VHN-79149

PATCH

title:Centro grandeurl:https://www.swisscom.ch/en/residential/help/device/internet-router/centro-grande.html

Trust: 0.8

title:Swisscom Centro Grande DSL Router HNDS Service Certificate Verification Failure Verification Vulnerability Patchurl:https://www.cnvd.org.cn/patchInfo/show/58059

Trust: 0.6

title:Vx226x1_61400url:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=55768

Trust: 0.6

sources: CNVD: CNVD-2015-02889 // JVNDB: JVNDB-2015-002767 // CNNVD: CNNVD-201505-335

EXTERNAL IDS

db:NVDid:CVE-2015-1188

Trust: 3.5

db:BIDid:74391

Trust: 1.0

db:JVNDBid:JVNDB-2015-002767

Trust: 0.8

db:CNNVDid:CNNVD-201505-335

Trust: 0.7

db:OSVDBid:121451

Trust: 0.6

db:CNVDid:CNVD-2015-02889

Trust: 0.6

db:PACKETSTORMid:131672

Trust: 0.2

db:VULHUBid:VHN-79149

Trust: 0.1

sources: CNVD: CNVD-2015-02889 // VULHUB: VHN-79149 // BID: 74391 // JVNDB: JVNDB-2015-002767 // PACKETSTORM: 131672 // CNNVD: CNNVD-201505-335 // NVD: CVE-2015-1188

REFERENCES

url:http://seclists.org/fulldisclosure/2015/apr/103

Trust: 2.8

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2015-1188

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2015-1188

Trust: 0.8

url:http://osvdb.org/show/osvdb/121451

Trust: 0.6

url:https://www.swisscom.ch/en/residential/more/save-energy/router-centro-grande-adb.html

Trust: 0.3

url:http://hackingcorp.ch/)

Trust: 0.1

url:https://www.swisscom.ch/en/residential/help/device/internet-router/centro-grande.html

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2015-1188

Trust: 0.1

url:http://www.swisscom.com/security

Trust: 0.1

sources: CNVD: CNVD-2015-02889 // VULHUB: VHN-79149 // BID: 74391 // JVNDB: JVNDB-2015-002767 // PACKETSTORM: 131672 // CNNVD: CNNVD-201505-335 // NVD: CVE-2015-1188

CREDITS

Ivan Almuina

Trust: 1.0

sources: BID: 74391 // PACKETSTORM: 131672 // CNNVD: CNNVD-201505-335

SOURCES

db:CNVDid:CNVD-2015-02889
db:VULHUBid:VHN-79149
db:BIDid:74391
db:JVNDBid:JVNDB-2015-002767
db:PACKETSTORMid:131672
db:CNNVDid:CNNVD-201505-335
db:NVDid:CVE-2015-1188

LAST UPDATE DATE

2025-04-12T23:29:32.242000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2015-02889date:2015-05-06T00:00:00
db:VULHUBid:VHN-79149date:2021-01-05T00:00:00
db:BIDid:74391date:2015-04-29T00:00:00
db:JVNDBid:JVNDB-2015-002767date:2015-05-22T00:00:00
db:CNNVDid:CNNVD-201505-335date:2021-01-12T00:00:00
db:NVDid:CVE-2015-1188date:2025-04-12T10:46:40.837

SOURCES RELEASE DATE

db:CNVDid:CNVD-2015-02889date:2015-05-06T00:00:00
db:VULHUBid:VHN-79149date:2015-05-20T00:00:00
db:BIDid:74391date:2015-04-29T00:00:00
db:JVNDBid:JVNDB-2015-002767date:2015-05-22T00:00:00
db:PACKETSTORMid:131672date:2015-04-29T13:43:13
db:CNNVDid:CNNVD-201505-335date:2015-04-29T00:00:00
db:NVDid:CVE-2015-1188date:2015-05-20T18:59:04.823