TURCK BL20 And BL67 CVE-2012-4697 FTP Hardcoded Credentials Security Bypass Vulnerability
BID:59979
Info
TURCK BL20 And BL67 CVE-2012-4697 FTP Hardcoded Credentials Security Bypass Vulnerability
| Bugtraq ID: | 59979 |
| Class: | Access Validation Error |
| CVE: |
CVE-2012-4697 |
| Remote: | Yes |
| Local: | No |
| Published: | May 16 2013 12:00AM |
| Updated: | May 16 2013 12:00AM |
| Credit: | Rubén Santamarta of IOActive |
| Vulnerable: |
TURCK BL67 Programmable Gateway 0 TURCK BL20 Programmable Gateway 0 |
| Not Vulnerable: | |
Discussion
TURCK BL20 And BL67 CVE-2012-4697 FTP Hardcoded Credentials Security Bypass Vulnerability
TURCK BL20 and BL67 are prone to a security-bypass vulnerability.
Remote attackers can exploit this issue to bypass the authentication mechanism and gain unauthorized administrative access to the device, which will aid in further attacks.
http://drupal.org/node/207891
TURCK BL20 and BL67 are prone to a security-bypass vulnerability.
Remote attackers can exploit this issue to bypass the authentication mechanism and gain unauthorized administrative access to the device, which will aid in further attacks.
http://drupal.org/node/207891
Exploit / POC
TURCK BL20 And BL67 CVE-2012-4697 FTP Hardcoded Credentials Security Bypass Vulnerability
An attacker can exploit this issue using readily available tools.
An attacker can exploit this issue using readily available tools.
References
TURCK BL20 And BL67 CVE-2012-4697 FTP Hardcoded Credentials Security Bypass Vulnerability
References:
References: