ID

VAR-201907-1314


CVE

CVE-2019-1010136


TITLE

ChinaMobile GPN2.4P21-C-CN Access control vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2019-006724

DESCRIPTION

ChinaMobile GPN2.4P21-C-CN W2001EN-00 is affected by: Incorrect Access Control - Unauthenticated Remote Reboot. The impact is: PLC Wireless Router's are vulnerable to an unauthenticated remote reboot due. The component is: Reboot settings are available to unauthenticated users instead of only authenticaed users. The attack vector is: Remote. ChinaMobile GPN2.4P21-C-CN Contains an access control vulnerability.Service operation interruption (DoS) There is a possibility of being put into a state. ChinaMobile GPN2.4P21-C-CN is a wireless router of China Mobile (ChinaMobile). There is an access control error vulnerability in ChinaMobile GPN2.4P21-C-CN W2001EN-00 version. This vulnerability stems from network systems or products not properly restricting access to resources from unauthorized roles

Trust: 1.71

sources: NVD: CVE-2019-1010136 // JVNDB: JVNDB-2019-006724 // VULHUB: VHN-141412

AFFECTED PRODUCTS

vendor:chinamobileltdmodel:gpn2.4p21-c-cnscope:eqversion:w2001en-00

Trust: 1.0

vendor:mobilemodel:gpn2.4p21-c-cnscope:eqversion:w2001en-00

Trust: 0.8

sources: JVNDB: JVNDB-2019-006724 // NVD: CVE-2019-1010136

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2019-1010136
value: HIGH

Trust: 1.0

NVD: CVE-2019-1010136
value: HIGH

Trust: 0.8

CNNVD: CNNVD-201907-1119
value: HIGH

Trust: 0.6

VULHUB: VHN-141412
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2019-1010136
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-141412
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2019-1010136
baseSeverity: HIGH
baseScore: 7.5
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 3.6
version: 3.0

Trust: 1.8

sources: VULHUB: VHN-141412 // JVNDB: JVNDB-2019-006724 // CNNVD: CNNVD-201907-1119 // NVD: CVE-2019-1010136

PROBLEMTYPE DATA

problemtype:CWE-306

Trust: 1.1

problemtype:CWE-284

Trust: 0.9

sources: VULHUB: VHN-141412 // JVNDB: JVNDB-2019-006724 // NVD: CVE-2019-1010136

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201907-1119

TYPE

access control error

Trust: 0.6

sources: CNNVD: CNNVD-201907-1119

CONFIGURATIONS

sources: JVNDB: JVNDB-2019-006724

PATCH

title:Top Pageurl:https://www.chinamobileltd.com/en/global/home.php

Trust: 0.8

sources: JVNDB: JVNDB-2019-006724

EXTERNAL IDS

db:EXPLOIT-DBid:45187

Trust: 2.5

db:NVDid:CVE-2019-1010136

Trust: 2.5

db:JVNDBid:JVNDB-2019-006724

Trust: 0.8

db:CNNVDid:CNNVD-201907-1119

Trust: 0.7

db:VULHUBid:VHN-141412

Trust: 0.1

sources: VULHUB: VHN-141412 // JVNDB: JVNDB-2019-006724 // CNNVD: CNNVD-201907-1119 // NVD: CVE-2019-1010136

REFERENCES

url:https://www.exploit-db.com/exploits/45187/

Trust: 1.7

url:https://www.shodan.io/search?query=title%3aplc++pstval-%3evalue%3ahtml%2findex.html

Trust: 1.7

url:https://nvd.nist.gov/vuln/detail/cve-2019-1010136

Trust: 1.4

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2019-1010136

Trust: 0.8

url:https://www.exploit-db.com/exploits/45187

Trust: 0.8

sources: VULHUB: VHN-141412 // JVNDB: JVNDB-2019-006724 // CNNVD: CNNVD-201907-1119 // NVD: CVE-2019-1010136

SOURCES

db:VULHUBid:VHN-141412
db:JVNDBid:JVNDB-2019-006724
db:CNNVDid:CNNVD-201907-1119
db:NVDid:CVE-2019-1010136

LAST UPDATE DATE

2024-11-23T22:44:56.562000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-141412date:2020-08-24T00:00:00
db:JVNDBid:JVNDB-2019-006724date:2019-07-25T00:00:00
db:CNNVDid:CNNVD-201907-1119date:2020-08-25T00:00:00
db:NVDid:CVE-2019-1010136date:2024-11-21T04:17:59.197

SOURCES RELEASE DATE

db:VULHUBid:VHN-141412date:2019-07-19T00:00:00
db:JVNDBid:JVNDB-2019-006724date:2019-07-25T00:00:00
db:CNNVDid:CNNVD-201907-1119date:2019-07-19T00:00:00
db:NVDid:CVE-2019-1010136date:2019-07-19T16:15:12.243