V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
CVE-2018-20219
CVE
HighConfirmedExploit available

An issue was discovered on Teracue ENC-400 devices with firmware 2.56 and below. After successful authentication, the device sends an authe…

CVSS
8.1
High
EPSS
0.43
p97
Published
2018-01-01
Updated
2018-01-01
Description

An issue was discovered on Teracue ENC-400 devices with firmware 2.56 and below. After successful authentication, the device sends an authentication cookie to the end user such that they can access the devices web administration panel. This token is hard-coded to a string in the source code (/usr/share/www/check.lp file). By setting this cookie in a browser, an attacker is able to maintain access to every ENC-400 device without knowing the password, which results in authentication bypass. Even if a user changes the password on the device, this token is static and unchanged.

Tags · CWE
Pre-auth
CWE-798
CAPEC-70
CAPEC-191
Affected products
Enc-400_hdmi2_firmwareEnc-400_hdmi_firmwareEnc-400_hdsdi_firmware
CVSS vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Timeline
2018-01-01
Published
2018-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: H
High (H)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.429 · p97
Known exploited (KEV)
No
MITRE ATT&CK
Inferred via CAPEC
└ via CAPEC-70 · CWE-798
└ via CAPEC-191 · CWE-798
Known exploits — Сканер-ВС
46451
exploitdb · https://www.exploit-db.com/exploits/46451
Enterprise
Affected software
ProductVendorStatus
enc-400_hdmi2_firmware*Tracked
enc-400_hdmi_firmware*Tracked
enc-400_hdsdi_firmware*Tracked
Source databases
CVE