Dell TrueMobile 2300 Remote Credential Reset Vulnerability
BID:15770
Info
Dell TrueMobile 2300 Remote Credential Reset Vulnerability
| Bugtraq ID: | 15770 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 07 2005 12:00AM |
| Updated: | Dec 07 2005 12:00AM |
| Credit: | Discovery credited to TNull. |
| Vulnerable: |
Dell TrueMobile 2300 Firmware 5.1.1 .6 Dell TrueMobile 2300 Firmware 3.0 .08 |
| Not Vulnerable: | |
Discussion
Dell TrueMobile 2300 Remote Credential Reset Vulnerability
It is possible for remote attackers to gain control of a target TrueMobile 2300 running firmware versions 3.0.0.8 and 5.1.1.6. Other versions are likely affected. The vulnerability appears to be in an administrative component accessed through the web-based control interface. Unauthenticated attackers can force the device to reset the administrative credentials without authorization. Once credentials have been reset an attacker can log in and perform malicious actions, potentially compromising the entire LAN behind the device.
It is possible for remote attackers to gain control of a target TrueMobile 2300 running firmware versions 3.0.0.8 and 5.1.1.6. Other versions are likely affected. The vulnerability appears to be in an administrative component accessed through the web-based control interface. Unauthenticated attackers can force the device to reset the administrative credentials without authorization. Once credentials have been reset an attacker can log in and perform malicious actions, potentially compromising the entire LAN behind the device.
Exploit / POC
Dell TrueMobile 2300 Remote Credential Reset Vulnerability
The attacker need only request:
http://target/apply.cgi?Page=adv_password.asp&action=ClearLog
A dialog requesting credentials may appear. The action will be performed, even if "cancel" is clicked.
The attacker need only request:
http://target/apply.cgi?Page=adv_password.asp&action=ClearLog
A dialog requesting credentials may appear. The action will be performed, even if "cancel" is clicked.
Solution / Fix
Dell TrueMobile 2300 Remote Credential Reset Vulnerability
Solution:
The vendor is aware of this vulnerability but will not be releasing a patch or upgrade, according to the original advisory.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
The vendor is aware of this vulnerability but will not be releasing a patch or upgrade, according to the original advisory.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Dell TrueMobile 2300 Remote Credential Reset Vulnerability
References:
References: