CVE-2018-20219
Summary
| CVE | CVE-2018-20219 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-03-21 16:00:00 UTC |
| Updated | 2019-03-25 19:53:00 UTC |
| Description | An issue was discovered on Teracue ENC-400 devices with firmware 2.56 and below. After successful authentication, the device sends an authentication cookie to the end user such that they can access the devices web administration panel. This token is hard-coded to a string in the source code (/usr/share/www/check.lp file). By setting this cookie in a browser, an attacker is able to maintain access to every ENC-400 device without knowing the password, which results in authentication bypass. Even if a user changes the password on the device, this token is static and unchanged. |
Risk And Classification
Problem Types: CWE-798
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Teracue | Enc-400 Hdmi | - | All | All | All |
| Hardware | Teracue | Enc-400 Hdmi | - | All | All | All |
| Hardware | Teracue | Enc-400 Hdmi2 | - | All | All | All |
| Hardware | Teracue | Enc-400 Hdmi2 | - | All | All | All |
| Operating System | Teracue | Enc-400 Hdmi2 Firmware | All | All | All | All |
| Operating System | Teracue | Enc-400 Hdmi Firmware | All | All | All | All |
| Hardware | Teracue | Enc-400 Hdsdi | - | All | All | All |
| Hardware | Teracue | Enc-400 Hdsdi | - | All | All | All |
| Operating System | Teracue | Enc-400 Hdsdi Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Teracue ENC-400 Command Injection / Missing Authentication ≈ Packet Storm | MISC | packetstormsecurity.com | Third Party Advisory, VDB Entry |
| ZX Security Limited - Information Security Consultants | MISC | zxsecurity.co.nz | Not Applicable |
| Full Disclosure: Multiple issues in Teracue ENC-400 including pre-authenticated remote code execution | MISC | seclists.org | Mailing List, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.