Eaton Network Shutdown Module Authentication Bypass Vulnerability
BID:31933
Info
Eaton Network Shutdown Module Authentication Bypass Vulnerability
| Bugtraq ID: | 31933 |
| Class: | Access Validation Error |
| CVE: |
CVE-2008-6816 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 27 2008 12:00AM |
| Updated: | Apr 16 2015 05:52PM |
| Credit: | Jan Rossmann and Jan Wagner of n.runs AG |
| Vulnerable: |
Eaton Network Shutdown Module 3.10 |
| Not Vulnerable: |
Eaton Network Shutdown Module 3.20 Eaton Network Shutdown Module 3.10 build 13 |
Discussion
Eaton Network Shutdown Module Authentication Bypass Vulnerability
Eaton Network Shutdown Module is prone to an authentication-bypass vulnerability caused by an unspecified error.
Attackers can exploit this vulnerability to define and execute custom actions within the Network Shutdown Module interface. This may allow attackers to execute arbitrary code within the context of the vulnerable application.
Versions prior to Network Shutdown Module 3.10 build 13 are affected.
Eaton Network Shutdown Module is prone to an authentication-bypass vulnerability caused by an unspecified error.
Attackers can exploit this vulnerability to define and execute custom actions within the Network Shutdown Module interface. This may allow attackers to execute arbitrary code within the context of the vulnerable application.
Versions prior to Network Shutdown Module 3.10 build 13 are affected.
Exploit / POC
Eaton Network Shutdown Module Authentication Bypass Vulnerability
Attackers can exploit this issue via a web browser.
Attackers can exploit this issue via a web browser.
Solution / Fix
Eaton Network Shutdown Module Authentication Bypass Vulnerability
Solution:
The vendor has released fixes to address this issue. Please see the references for more information.
Solution:
The vendor has released fixes to address this issue. Please see the references for more information.
References
Eaton Network Shutdown Module Authentication Bypass Vulnerability
References:
References: