UTC Fire & Security GE-MC100-NTP/GPS-ZB Default Credentials Authentication Bypass Vulnerability
BID:52083
Info
UTC Fire & Security GE-MC100-NTP/GPS-ZB Default Credentials Authentication Bypass Vulnerability
| Bugtraq ID: | 52083 |
| Class: | Design Error |
| CVE: |
CVE-2012-1288 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 20 2012 12:00AM |
| Updated: | Feb 24 2012 05:50PM |
| Credit: | Temple Murphy |
| Vulnerable: |
UTC Fire & Security GE-MC100-NTP/GPS-ZB 0 |
| Not Vulnerable: | |
Discussion
UTC Fire & Security GE-MC100-NTP/GPS-ZB Default Credentials Authentication Bypass Vulnerability
UTC Fire & Security GE-MC100-NTP/GPS-ZB master clock is prone to a remote authentication-bypass vulnerability.
An attacker can exploit this issue to gain unauthorized administrative access to the affected device. Successful exploits will result in the complete compromise of the affected device.
UTC Fire & Security GE-MC100-NTP/GPS-ZB master clock is prone to a remote authentication-bypass vulnerability.
An attacker can exploit this issue to gain unauthorized administrative access to the affected device. Successful exploits will result in the complete compromise of the affected device.
Exploit / POC
UTC Fire & Security GE-MC100-NTP/GPS-ZB Default Credentials Authentication Bypass Vulnerability
Attackers can use readily available tools or browser to exploit this issue.
Attackers can use readily available tools or browser to exploit this issue.
Solution / Fix
UTC Fire & Security GE-MC100-NTP/GPS-ZB Default Credentials Authentication Bypass Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
UTC Fire & Security GE-MC100-NTP/GPS-ZB Default Credentials Authentication Bypass Vulnerability
References:
References:
- GE-MC100-NTP/GPS-ZB Homepage (UTC Fire & Security)
- UTC Fire & Security Master Clock contains hardcoded default administrator login (US-CERT)