Computrols CBAS Web ICSA-19-141-01 Multiple Security Vulnerabilities
BID:108415
Info
Computrols CBAS Web ICSA-19-141-01 Multiple Security Vulnerabilities
| Bugtraq ID: | 108415 |
| Class: | Input Validation Error |
| CVE: |
CVE-2019-10847 CVE-2019-10848 CVE-2019-10846 CVE-2019-10854 CVE-2019-10849 CVE-2019-10851 CVE-2019-10855 CVE-2019-10852 CVE-2019-10853 |
| Remote: | Yes |
| Local: | No |
| Published: | May 21 2019 12:00AM |
| Updated: | May 21 2019 12:00AM |
| Credit: | Gjoko Krstic of Applied Risk |
| Vulnerable: |
Computrols CBAS Web 8 Computrols CBAS Web 7 Computrols CBAS Web 4 Computrols CBAS Web 3 Computrols CBAS Web 19 Computrols CBAS Web 18 Computrols CBAS Web 15 Computrols CBAS Web 14 |
| Not Vulnerable: |
Computrols CBAS Web 19.0.1 Computrols CBAS Web 18.0.1 Computrols CBAS Web 15.0.1 Computrols CBAS Web 14.0.1 Computrols CBAS Web 8.0.7 Computrols CBAS Web 7.2.1 Beta Computrols CBAS Web 6.9.2 Computrols CBAS Web 4.8.2 Computrols CBAS Web 3.15.1 |
Discussion
Computrols CBAS Web ICSA-19-141-01 Multiple Security Vulnerabilities
Computrols CBAS Web is prone to following security vulnerabilities:
1. Multiple information disclosure vulnerabilities
2. A cross-site-scripting vulnerability
3. A remote command injection vulnerability
4. A cross-site request forgery vulnerability
5. A SQL injection vulnerability
6. An authentication bypass vulnerability
An attacker may exploit these issues to execute arbitrary commands or arbitrary HTML or script code in the browser of an unsuspecting user within the context of the affected application and steal cookie-based authentication credentials and aid in further attacks, compromise the application, access or modify data, exploit latent vulnerabilities in the underlying database, bypass security restrictions and perform unauthorized actions, disclose sensitive information.
Computrols CBAS Web is prone to following security vulnerabilities:
1. Multiple information disclosure vulnerabilities
2. A cross-site-scripting vulnerability
3. A remote command injection vulnerability
4. A cross-site request forgery vulnerability
5. A SQL injection vulnerability
6. An authentication bypass vulnerability
An attacker may exploit these issues to execute arbitrary commands or arbitrary HTML or script code in the browser of an unsuspecting user within the context of the affected application and steal cookie-based authentication credentials and aid in further attacks, compromise the application, access or modify data, exploit latent vulnerabilities in the underlying database, bypass security restrictions and perform unauthorized actions, disclose sensitive information.
Exploit / POC
Computrols CBAS Web ICSA-19-141-01 Multiple Security Vulnerabilities
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Computrols CBAS Web ICSA-19-141-01 Multiple Security Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Computrols CBAS Web ICSA-19-141-01 Multiple Security Vulnerabilities
References:
References:
- Advisory (ICSA-19-141-01) Computrols CBAS Web (ICS-CERT)
- CBAS Productpage (computrols)
- Computrols Homepage (computrols)