SmartLine DeviceLock Unauthorized Access Vulnerability
BID:19500
CVE-2006-4184 |Info
SmartLine DeviceLock Unauthorized Access Vulnerability
| Bugtraq ID: | 19500 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jul 14 2006 12:00AM |
| Updated: | Aug 16 2006 10:25PM |
| Credit: | seppi has been credited with the discovery of this vulnerability. |
| Vulnerable: |
SmartLine Device Manager 5.73 |
| Not Vulnerable: |
SmartLine Device Manager 6.0 SmartLine Device Manager 5.73 Build 305 |
Discussion
SmartLine DeviceLock Unauthorized Access Vulnerability
SmartLine DeviceLock is prone to an unauthorized access vulnerability because the application fails to apply proper access-control restrictions to various devices.
An attacker can exploit this issue to gain administrative privileges; other attacks are also possible.
Version 5.73 is vulnerable to this issue; other versions may also be affected.
SmartLine DeviceLock is prone to an unauthorized access vulnerability because the application fails to apply proper access-control restrictions to various devices.
An attacker can exploit this issue to gain administrative privileges; other attacks are also possible.
Version 5.73 is vulnerable to this issue; other versions may also be affected.
Exploit / POC
SmartLine DeviceLock Unauthorized Access Vulnerability
To exploit this issue, attackers use raw disk editing and access utilities.
To exploit this issue, attackers use raw disk editing and access utilities.
Solution / Fix
SmartLine DeviceLock Unauthorized Access Vulnerability
Solution:
The vendor has released DeviceLock 5.73 Build 305 and DeviceLock 6.0 to address this issue. Please contact the vendor for details.
Solution:
The vendor has released DeviceLock 5.73 Build 305 and DeviceLock 6.0 to address this issue. Please contact the vendor for details.
References
SmartLine DeviceLock Unauthorized Access Vulnerability
References:
References: