AK-Systems Windows Terminals Remote Unauthorized Administrative Access Vulnerability
BID:19659
CVE-2006-4309 |Info
AK-Systems Windows Terminals Remote Unauthorized Administrative Access Vulnerability
| Bugtraq ID: | 19659 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 22 2006 12:00AM |
| Updated: | Aug 30 2006 08:48PM |
| Credit: | Victor Sudakov <[email protected]> discovered this issue. |
| Vulnerable: |
AK-Systems Windows Terminal 1.2.5 ExVLP |
| Not Vulnerable: | |
Discussion
AK-Systems Windows Terminals Remote Unauthorized Administrative Access Vulnerability
AK-Systems Windows Terminals are prone to a remote unauthorized administrative access vulnerability. This issue is due to a lack of authentication requirements for remote administrative access to affected devices.
This issue allows remote attackers to gain administrative access on affected devices without requiring authentication. This allows attackers to compromise affected devices and to monitor or access RDP and Citrix sessions on targeted devices.
Devices with firmware version 1.2.5 ExVLP are vulnerable to this issue. Other versions may also be affected.
AK-Systems Windows Terminals are prone to a remote unauthorized administrative access vulnerability. This issue is due to a lack of authentication requirements for remote administrative access to affected devices.
This issue allows remote attackers to gain administrative access on affected devices without requiring authentication. This allows attackers to compromise affected devices and to monitor or access RDP and Citrix sessions on targeted devices.
Devices with firmware version 1.2.5 ExVLP are vulnerable to this issue. Other versions may also be affected.
Exploit / POC
AK-Systems Windows Terminals Remote Unauthorized Administrative Access Vulnerability
Attackers use a VNC client application to exploit this issue.
Attackers use a VNC client application to exploit this issue.
Solution / Fix
AK-Systems Windows Terminals Remote Unauthorized Administrative Access Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
References
AK-Systems Windows Terminals Remote Unauthorized Administrative Access Vulnerability
References:
References:
- AK-Systems Product Page (AK-Systems)
- unauthorized VNC access in AK-Systems Windows Terminals (Victor Sudakov
)