[<prev] [next>] [day] [month] [year] [list]
Message-ID: <d24fffa2-abd9-71f9-22fd-d48484358b92@mazars.be>
Date: Mon, 7 Oct 2019 13:05:35 +0000
From: "TIMMERMAN, Jens" <jens.timmerman@...ars.be>
To: "fulldisclosure@...lists.org" <fulldisclosure@...lists.org>
Subject: [FD] Password disclosure in the web interface on socomec DIRIS A-40
devices before 48250501
[description]
Password disclosure in the web interface on socomec DIRIS A-40 devices before 48250501 allows a remote attacker to get full access to a device via the
/password.jsn URI.
------------------------------------------
[Vulnerability Type]
Incorrect Access Control
------------------------------------------
[Vendor of Product]
Socomec (https://www.socomec.com)
------------------------------------------
[Affected Product Code Base]
DIRIS A-40 https://www.socomec.com/single-circuit-multifunction-meters_en.html - all versions before ref 48250501
------------------------------------------
[Affected Component]
web interface
------------------------------------------
[Attack Type]
Remote
------------------------------------------
[Impact Denial of Service]
true
------------------------------------------
[Impact Information Disclosure]
true
------------------------------------------
[Attack Vectors]
An attacker visiting http://<device ip>/password.jsn can view the
devices usernames and passwords in cleartext and use these to get full
administrative control over the device.
------------------------------------------
[Has vendor confirmed or acknowledged the vulnerability?]
true
------------------------------------------
[Discoverer]
Jens Timmerman (Mazars)
------------------------------------------
[Reference]
https://www.socomec.com/single-circuit-multifunction-meters_en.html
CVE-2019-15859
Download attachment "0xAD760CC853549596.asc" of type "application/pgp-keys" (12955 bytes)
Download attachment "signature.asc" of type "application/pgp-signature" (834 bytes)
_______________________________________________
Sent through the Full Disclosure mailing list
https://nmap.org/mailman/listinfo/fulldisclosure
Web Archives & RSS: http://seclists.org/fulldisclosure/
Powered by blists - more mailing lists