VARIoT IoT vulnerabilities database
| VAR-201308-0210 | CVE-2013-3462 | Cisco Unified Communications Manager Vulnerable to buffer overflow |
CVSS V2: 8.5 CVSS V3: - Severity: HIGH |
Buffer overflow in Cisco Unified Communications Manager (Unified CM) 7.1(x) before 7.1(5b)su6, 8.5(x) before 8.5(1)su6, 8.6(x) before 8.6(2a)su3, and 9.x before 9.1(2) allows remote authenticated users to execute arbitrary code via unspecified vectors, aka Bug ID CSCud54358.
Attackers can exploit this issue to execute arbitrary code within the context of the affected application. Failed exploit attempts will result in denial-of-service conditions.
This issue is being tracked by Cisco Bug ID CSCud54358. This component provides a scalable, distributed and highly available enterprise IP telephony call processing solution. The following releases are affected: Cisco Unified CM 7.1(x) prior to 7.1(5b)su6, 8.5(x) prior to 8.5(1)su6, 8.6(x) prior to 8.6(2a)su3, 9.1(2 ) prior to 9.x versions
| VAR-201308-0220 | CVE-2013-3453 | Cisco Unified Communications Manager and Cisco Unified Presence Service disruption in (DoS) Vulnerabilities |
CVSS V2: 7.8 CVSS V3: - Severity: HIGH |
Memory leak in Cisco Unified Communications Manager IM and Presence Service before 8.6(5)SU1 and 9.x before 9.1(2), and Cisco Unified Presence, allows remote attackers to cause a denial of service (memory and CPU consumption) by making many TCP connections to port (1) 5060 or (2) 5061, aka Bug ID CSCud84959.
Attackers can exploit this issue to cause a denial of service condition.
This issue is being tracked by Cisco Bug ID CSCud84959. CUCM is a call processing component in a unified communication system
| VAR-201312-0126 | CVE-2013-4775 |
plural NETGEAR ProSafe Vulnerability to read encrypted administrator authentication information in switch product firmware
Related entries in the VARIoT exploits database: VAR-E-201308-0138, VAR-E-201308-0137 |
CVSS V2: 7.8 CVSS V3: - Severity: HIGH |
NETGEAR ProSafe GS724Tv3 and GS716Tv2 with firmware 5.4.1.13 and earlier; GS748Tv4 with firmware 5.4.1.14; GS510TP with firmware 5.4.0.6; GS752TPS, GS728TPS, GS728TS, and GS725TS with firmware 5.3.0.17; and GS752TXS and GS728TXS with firmware 6.1.0.12 allows remote attackers to read encrypted administrator credentials and other startup configurations via a direct request to filesystem/startup-config. NetGear ProSafe is a smart switch product that monitors and configures the network. An information disclosure vulnerability exists in multiple NetGear ProSafe switches. An attacker can exploit a vulnerability to download a configuration file and reveal sensitive information. The information obtained may be helpful for further attacks. 1. BACKGROUND
According to the vendor, Netgear ProSafe is a cost-effective line of smart switches for Small and Medium Businesses (SMBs). The products cover an essential set of network features and easy-to-use web-based management. Power over Ethernet (PoE) and Stacking versions are also available.
2.
CVE-2013-4776: Denial of Service vulnerability.
3. AFFECTED PRODUCTS AND SOFTWARE
CVE-2013-4775
GS724Tv3 and GS716Tv2 - firmware 5.4.1.13
GS724Tv3 and GS716Tv2 - firmware 5.4.1.10
GS748Tv4 - firmware 5.4.1.14
GS510TP - firmware 5.4.0.6
GS752TPS and GS728TPS - firmware 5.3.0.17
GS728TS and GS725TS - firmware 5.3.0.17
GS752TXS and GS728TXS - firmware 6.1.0.12
CVE-2013-4776
GS724Tv3 and GS716Tv2 - firmware 5.4.1.13
GS724Tv3 and GS716Tv2 - firmware 5.4.1.10
GS748Tv4 - firmware 5.4.1.14
GS510TP - firmware 5.0.4.4
4. VULNERABILITIES
The list below describes the vulnerabilities discovered in the affected software.
4.1 CVE-2013-4775: Unauthenticated startup-config disclosure
The web management application fails to restrict URL access to different application areas.
[Proof of Concept]
The vulnerability can be exploited with a simple HTTP (GET) request.
Open a browser and visit http://Target-IP/filesystem/startup-config
4.2 CVE-2013-4776: Denial of Service vulnerability
The affected products are prone to a Denial of Service vulnerability. Remote, unauthenticated
attackers could exploit this issue to cause a switch reboot or crash, resulting in a loss of
network connectivity for all devices connected to the switch.
[Proof of Concept]
The vulnerability can be exploited with a simple HTTP (GET) request.
Open a browser and visit http://Target-IP/filesystem/
Implementation of a Proof of Concept for both vulnerabilities can be found here:
http://www.encripto.no/tools/netgear-prosafe-PoC.tar.gz
5. REMEDIATION
No firmware updates or fixes have been released yet.
As a mitigation, the vendor recommends configuring a separate management VLAN and configure
access control via \x93Security::Access::Access Control\x94 or \x93Security::ACL::Advanced::IP Extended Rules\x94.
6. CREDIT
The vulnerabilities were originally discovered in a GS724Tv3 device, by Juan J. G\xfcelfo at Encripto AS.
E-mail: post [at] encripto [dot] no
Web: http://www.encripto.no
Special thanks to Maarten Hoogcarspel and the Netgear Support Team for verifying other switch
models, and considering possible fixes.
For more information about Encripto\x92s research policy, please visit http://www.encripto.no/forskning/
7. REFERENCES
http://www.encripto.no/forskning/whitepapers/Netgear_prosafe_advisory_aug_2013.pdf
http://www.encripto.no/tools/netgear-prosafe-PoC.tar.gz
DISCLAIMER
The material presented in this document is for educational purposes only. Encripto AS cannot be
responsible for any loss or damage carried out by any technique presented in this material. The reader is
the only one responsible for applying this knowledge, which is at his / her own risk.
Any of the trademarks, service marks, collective marks, design rights, personality rights or similar rights
that are mentioned, used or cited in this document is property of their respective owners
| VAR-201312-0127 | CVE-2013-4776 |
plural NETGEAR ProSafe Service operation interruption in switch product firmware (DoS) Vulnerabilities
Related entries in the VARIoT exploits database: VAR-E-201308-0138, VAR-E-201308-0137 |
CVSS V2: 7.8 CVSS V3: - Severity: HIGH |
NETGEAR ProSafe GS724Tv3 and GS716Tv2 with firmware 5.4.1.13 and earlier, GS748Tv4 5.4.1.14, and GS510TP 5.0.4.4 allows remote attackers to cause a denial of service (reboot or crash) via a crafted HTTP request to filesystem/. NetGear ProSafe is a smart switch product that monitors and configures the network.
Successfully exploiting this issue allows remote attackers to cause denial-of-service conditions.
The following ProSafe products are vulnerable:
GS724Tv3 firmware version 5.4.1.13
GS716Tv2 firmware version 5.4.1.13
GS724Tv3 firmware version 5.4.1.10
GS716Tv2 firmware version 5.4.1.10
GS748Tv4 firmware version 5.4.1.14
GS510TP firmware version 5.0.4.4. 1. BACKGROUND
According to the vendor, Netgear ProSafe is a cost-effective line of smart switches for Small and Medium Businesses (SMBs). The products cover an essential set of network features and easy-to-use web-based management. Power over Ethernet (PoE) and Stacking versions are also available.
2. SUMMARY
A range of ProSafe switches are affected by two different vulnerabilities:
CVE-2013-4775: Unauthenticated startup-config disclosure.
CVE-2013-4776: Denial of Service vulnerability.
3. VULNERABILITIES
The list below describes the vulnerabilities discovered in the affected software.
4.1 CVE-2013-4775: Unauthenticated startup-config disclosure
The web management application fails to restrict URL access to different application areas.
[Proof of Concept]
The vulnerability can be exploited with a simple HTTP (GET) request.
Open a browser and visit http://Target-IP/filesystem/startup-config
4.2 CVE-2013-4776: Denial of Service vulnerability
The affected products are prone to a Denial of Service vulnerability.
[Proof of Concept]
The vulnerability can be exploited with a simple HTTP (GET) request.
Open a browser and visit http://Target-IP/filesystem/
Implementation of a Proof of Concept for both vulnerabilities can be found here:
http://www.encripto.no/tools/netgear-prosafe-PoC.tar.gz
5. REMEDIATION
No firmware updates or fixes have been released yet.
As a mitigation, the vendor recommends configuring a separate management VLAN and configure
access control via \x93Security::Access::Access Control\x94 or \x93Security::ACL::Advanced::IP Extended Rules\x94.
6. CREDIT
The vulnerabilities were originally discovered in a GS724Tv3 device, by Juan J. G\xfcelfo at Encripto AS.
E-mail: post [at] encripto [dot] no
Web: http://www.encripto.no
Special thanks to Maarten Hoogcarspel and the Netgear Support Team for verifying other switch
models, and considering possible fixes.
For more information about Encripto\x92s research policy, please visit http://www.encripto.no/forskning/
7. REFERENCES
http://www.encripto.no/forskning/whitepapers/Netgear_prosafe_advisory_aug_2013.pdf
http://www.encripto.no/tools/netgear-prosafe-PoC.tar.gz
DISCLAIMER
The material presented in this document is for educational purposes only. Encripto AS cannot be
responsible for any loss or damage carried out by any technique presented in this material. The reader is
the only one responsible for applying this knowledge, which is at his / her own risk.
Any of the trademarks, service marks, collective marks, design rights, personality rights or similar rights
that are mentioned, used or cited in this document is property of their respective owners
| VAR-201308-0085 | CVE-2013-3388 | Cisco Prime Central for Hosted Collaboration Solution Assurance Service disruption in (DoS) Vulnerabilities |
CVSS V2: 7.8 CVSS V3: - Severity: HIGH |
Cisco Prime Central for Hosted Collaboration Solution (HCS) Assurance 8.6 and 9.x before 9.2(1) allows remote attackers to cause a denial of service (memory consumption) via a flood of TCP packets to port 44444, aka Bug ID CSCtz92776.
Attackers can exploit this issue to cause excessive memory consumption, resulting in denial-of-service conditions.
This issue is being tracked by Cisco Bug ID CSCtz92776. The platform provides functions such as secure access authentication and real-time fault analysis
| VAR-201308-0225 | CVE-2013-3460 | Cisco Unified Communications Manager Service disruption in (DoS) Vulnerabilities |
CVSS V2: 7.8 CVSS V3: - Severity: HIGH |
Memory leak in Cisco Unified Communications Manager (Unified CM) 8.5(x) before 8.5(1)su6, 8.6(x) before 8.6(2a)su3, and 9.x before 9.1(1) allows remote attackers to cause a denial of service (service disruption) via a high rate of UDP packets, aka Bug ID CSCub85597. Vendors have confirmed this vulnerability Bug ID CSCub85597 It is released as.High load by a third party UDP Service disruption via packets ( Stop service ) There is a possibility of being put into a state.
A remote attacker may exploit this issue to cause denial-of-service conditions.
This issue is tracked by Cisco Bug ID CSCub85597. This component provides a scalable, distributed and highly available enterprise IP telephony call processing solution. The following releases are affected: Cisco Unified CM 8.5(x) prior to 8.5(1)su6, 8.6(x) prior to 8.6(2a)su3, 9.x prior to 9.1(1)
| VAR-201911-1468 | CVE-2013-3314 | Loftek Nexus 543 IP Camera Vulnerable to information disclosure |
CVSS V2: 5.0 CVSS V3: 7.5 Severity: HIGH |
The Loftek Nexus 543 IP Camera allows remote attackers to obtain (1) IP addresses via a request to get_realip.cgi or (2) firmware versions (ui and system), timestamp, serial number, p2p port number, and wifi status via a request to get_status.cgi. Loftek Nexus 543 IP Camera Contains an information disclosure vulnerability.Information may be obtained. Loftek Nexus 543 is prone to multiple information-disclosure vulnerabilities.
Successful exploits may allow attackers to disclose sensitive information that may aid in launching further attacks
| VAR-201308-0208 | CVE-2013-3585 |
Samsung Web Viewer for Samsung DVR allows authentication bypass and password disclosure
Related entries in the VARIoT exploits database: VAR-E-201308-0457 |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Samsung Web Viewer for Samsung DVR devices stores credentials in cleartext, which allows context-dependent attackers to obtain sensitive information via vectors involving (1) direct access to a file or (2) the user-setup web page. Samsung DVR is prone to a remote information-disclosure vulnerability.
Successful exploits will allow attackers to obtain sensitive information, such as credentials, that may aid in further attacks
| VAR-201309-0329 | CVE-2013-5723 | SAP NetWeaver ‘ ABAD0_DELETE_DERIVATION_TABLE 'function SQL Injection vulnerability |
CVSS V2: 7.5 CVSS V3: - Severity: HIGH |
SQL injection vulnerability in SAP NetWeaver 7.30 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, related to "ABAD0_DELETE_DERIVATION_TABLE.". Because some of the input passed to the \"ABAD0_DELETE_DERIVATION_TABLE\" function fails to filter properly before using the SQL query, the remote attacker manipulates the SQL query by injecting arbitrary SQL code. SAP NetWeaver is a set of service-oriented integrated application platform of German SAP company. The platform provides a development and runtime environment for SAP applications. The vulnerability stems from insufficient filtering of user-submitted data before the program constructs SQL query statements. Attackers can use this vulnerability to manipulate SQL query logic to perform unauthorized operations in the underlying database. There are vulnerabilities in SAP NetWeaver 7.30, other versions may also be affected
| VAR-201308-0443 | No CVE | Samsung DVR Multiple security bypass vulnerabilities |
CVSS V2: - CVSS V3: - Severity: - |
Samsung DVR is a digital hard disk video recorder product of Samsung Company of South Korea. This product provides functions such as video recorder, screen division, PTZ lens control, alarm control, network transmission, etc.
There are multiple security bypasses in Samsung DVR 1.10 and earlier. Attackers can use these vulnerabilities to bypass specific security restrictions and perform unauthorized operations
| VAR-201308-0494 | No CVE | Sitecom N300/N600 Undocumented Telnet Service Vulnerability |
CVSS V2: 6.8 CVSS V3: - Severity: MEDIUM |
The Sitecom WLM-3500 and WLM-5500 devices have vulnerabilities that allow the Telnet service to be opened by accessing the \"http://<target-ip>/cgi-bin/telnetControl.cgi\" URL, which is accessible via the WAN interface and allows remote access. The attacker accesses and controls the device through the telnet service. The Sitecom WLM-3500 and WLM-5500 are wireless router products developed by Sitecom. The Sitecom WLM-3500 and WLM-5500 devices generate WPA2 ciphertext and WEB administrator user passwords based on the MAC address of the wireless interface card. Attackers in the Wi-Fi network range can calculate the default wireless password and access device. Multiple Sitecom products are prone to multiple authentication-bypass vulnerabilities.
Attackers can exploit these issues to gain unauthorized access to the device and perform unauthorized actions. This can lead to a complete compromise of the devices.
The following products are vulnerable:
Sitecom WLM-3500v2001 firmware 1.07
Sitecom WLM-5500v1001 firmware 1.15
| VAR-201308-0163 | CVE-2013-2782 | Schneider Electric Trio J-Series License Free Ethernet Radio Vulnerabilities that can break cryptographic protection mechanisms |
CVSS V2: 9.3 CVSS V3: - Severity: HIGH |
Schneider Electric Trio J-Series License Free Ethernet Radio with firmware 3.6.0 through 3.6.3 uses the same AES encryption key across different customers' installations, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by leveraging knowledge of this key from another installation. The Schneider Electric Multiple Trio J-Series Radio device is a radio station device. An attacker can exploit the vulnerability to intercept and reveal encrypted wireless traffic link traffic and access the ICS network. Schneider Electric provides total solutions for the energy and infrastructure, industrial, data center and network, building and residential markets in more than 100 countries. No detailed solution is currently available.
The above devices running V3.6.0, V3.6.1, V3.6.2 and V3.6.3 firmware are affected by this vulnerability
| VAR-201308-0171 | CVE-2013-2802 | Sixnet Universal Protocol Undocumented Function code remote security bypass vulnerability |
CVSS V2: 10.0 CVSS V3: - Severity: HIGH |
The universal protocol implementation in Sixnet UDR before 2.0 and RTU firmware before 4.8 allows remote attackers to execute arbitrary code; read, modify, or create files; or obtain file metadata via function opcodes. SIXNET is a long-established manufacturer of industrial automation and industrial Ethernet products. Since 1976, it has provided high quality control systems and industrial network communication products to users all over the world. The Sixnet Universal Protocol has a remote security bypass vulnerability. Both Sixnet UDR and RTU are products of SIXNET in the United States. UDR is a generic driver used in OPC servers. RTU is a data acquisition system suitable for energy metering and environmental monitoring. A security vulnerability exists in common protocol functions in versions prior to Sixnet UDR 2.0 and RTU firmware prior to 4.8
| VAR-201308-0129 | CVE-2013-0526 |
IBM Avocent 1754 KVM Runs on the switch GCM16 and GCM32 Vulnerable to arbitrary command execution
Related entries in the VARIoT exploits database: VAR-E-201308-0128 |
CVSS V2: 8.5 CVSS V3: - Severity: HIGH |
ping.php in Global Console Manager 16 (GCM16) and Global Console Manager 32 (GCM32) before 1.20.0.22575 on the IBM Avocent 1754 KVM switch allows remote authenticated users to execute arbitrary commands via shell metacharacters in the (1) count or (2) size parameter. The IBM 1754 GCM Series provides KVM and serial console management over IP in a single device. An attacker can exploit the vulnerability to execute arbitrary commands with root privileges. This vulnerability stems from a webapp variable not being properly filtered. The product supports AES encryption, LDAP and smart card/common access card (CAC) readers and more, enabling centralized authentication and local or remote system access
| VAR-201308-0279 | CVE-2013-5096 | Junos Space JA1500 Used in appliances Juniper Junos Space Vulnerabilities whose settings are changed |
CVSS V2: 4.0 CVSS V3: - Severity: MEDIUM |
Juniper Junos Space before 13.1R1.6, as used on the JA1500 appliance and in other contexts, does not properly implement role-based access control, which allows remote authenticated users to modify the configuration by leveraging the read-only privilege, aka PR 863804. Vendors have confirmed this vulnerability PR 863804 It is released as.Remotely authenticated users may change settings by using read-only privileges. Juniper Networks JUNOS Space is prone to a security-bypass vulnerability.
An attacker can exploit this issue to bypass certain security restrictions and perform unauthorized actions like making configuration changes. This may aid in further attacks.
Juniper Networks JUNOS Space versions 11.1, 11.2, 11.3, 12.1, 12.2 and 12.3 are vulnerable. The solution supports automated configuration, monitoring, and troubleshooting of devices and services throughout their lifecycle. A remote authorized attacker could exploit this vulnerability to modify the configuration with read-only permissions
| VAR-201312-0104 | CVE-2013-3572 | Ubiquiti Networks UniFi of UniFi Controller Administrator interface cross-site scripting vulnerability |
CVSS V2: 4.3 CVSS V3: 6.1 Severity: MEDIUM |
Cross-site scripting (XSS) vulnerability in the administer interface in the UniFi Controller in Ubiquiti Networks UniFi 2.3.5 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted client hostname. Ubiquiti Networks UniFi is prone to an HTML-injection vulnerability because it fails to sanitize user-supplied input.
Successful exploits will allow attacker-supplied HTML and script code to run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or control how the site is rendered to the user. Other attacks are also possible.
Ubiquiti Networks UniFi 2.3.5 and earlier are vulnerable. Ubiquiti Networks UniFi is a set of WiFi wireless network system of Ubiquiti Networks in the United States. UniFi Controller is one of those wireless controllers
| VAR-201308-0280 | CVE-2013-5097 | Junos Space JA1500 Used in appliances Juniper Junos Space Vulnerability in which important information is obtained |
CVSS V2: 4.0 CVSS V3: - Severity: MEDIUM |
Juniper Junos Space before 13.1R1.6, as used on the JA1500 appliance and in other contexts, does not properly restrict access to the list of user accounts and their MD5 password hashes, which makes it easier for remote authenticated users to obtain sensitive information via a dictionary attack, aka PR 879462. Vendors have confirmed this vulnerability PR 879462 It is released as.Dictionary attack by remotely authenticated user (dictionary attack) You may get important information through. Juniper Networks JUNOS Space is prone to multiple information-disclosure vulnerabilities.
Attackers can exploit these issues to obtain sensitive information that may aid in launching further attacks.
Juniper Networks JUNOS Space versions 11.1, 11.2, 11.3, 12.1, 12.2 and 12.3 are vulnerable. The solution supports automated configuration, monitoring, and troubleshooting of devices and services throughout their lifecycle
| VAR-201308-0278 | CVE-2013-5095 | Junos Space JA1500 Used in appliances Juniper Junos Space Vulnerable to cross-site scripting |
CVSS V2: 4.3 CVSS V3: - Severity: MEDIUM |
Cross-site scripting (XSS) vulnerability in the web-based interface in Juniper Junos Space before 13.1R1.6, as used on the JA1500 appliance and in other contexts, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka PR 884469. Vendors have confirmed this vulnerability PR 884469 It is released as.By any third party Web Script or HTML May be inserted.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks.
Juniper Networks JUNOS Space versions 11.1, 11.2, 11.3, 12.1, 12.2 and 12.3 are vulnerable. The solution supports automated configuration, monitoring, and troubleshooting of devices and services throughout their lifecycle
| VAR-201308-0205 | CVE-2013-3582 | Dell BIOS in some Latitude laptops and Precision Mobile Workstations vulnerable to buffer overflow |
CVSS V2: 7.6 CVSS V3: - Severity: HIGH |
Buffer overflow in Dell BIOS on Dell Latitude D###, E####, XT2, and Z600 devices, and Dell Precision M#### devices, allows local users to bypass intended BIOS signing requirements and install arbitrary BIOS images by leveraging administrative privileges and providing a crafted rbu_packet.pktNum value in conjunction with a crafted rbu_packet.pktSize value. Dell Multiple offers Latitude Laptop and Precision Mobile Workstation of BIOS A buffer overflow vulnerability exists in the update process. Dell Multiple offers Latitude Laptop and Precision Mobile Workstation Then BIOS In the update process, the update is performed after verifying the signature of the update image. This update process includes rbu_packet.pktNum and rbu_packet.pktSize A buffer overflow vulnerability exists due to the value of. By using this vulnerability, signature verification was avoided and crafted BIOS It becomes possible to update to.By having a specially crafted updater run, rootkit Or malicious code BIOS May be written.
Attackers may leverage these issues to execute arbitrary code in the context of the affected application. Failed attacks will cause denial-of-service conditions. Dell Latitude and Precision are a series of notebook computer products released by Dell in the United States. BIOS (Basic Input-Output System) is a set of programs solidified on the ROM chip on the computer motherboard. It stores the most important basic input and output programs of the computer, system setting information, and self-test programs after startup. and system self-starter
| VAR-201308-0212 | CVE-2013-3464 | Cisco IOS XR Service disruption in (DoS) Vulnerabilities |
CVSS V2: 4.6 CVSS V3: - Severity: MEDIUM |
Cisco IOS XR allows local users to cause a denial of service (Silicon Packet Processor memory corruption, improper mutex handling, and device reload) by starting an outbound flood of large ICMP Echo Request packets and stopping this with a CTRL-C sequence, aka Bug ID CSCui60347. Cisco IOS is the interconnected network operating system used on most Cisco system routers and network switches. A denial of service vulnerability exists in Cisco IOS XR Software. An attacker could exploit the vulnerability to cause a denial of service by sending a large number of ICMP echo request packets and a stop sequence.
A local attacker can exploit this issue to cause an affected device to reload, denying service to legitimate users.
This issue is being tracked by Cisco bug ID CSCui60347