Applied Watch Command Center Authentication Bypass Vulnerability
BID:9124
Info
Applied Watch Command Center Authentication Bypass Vulnerability
| Bugtraq ID: | 9124 |
| Class: | Access Validation Error |
| CVE: |
CVE-2003-0974 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 28 2003 12:00AM |
| Updated: | Jul 12 2009 12:56AM |
| Credit: | The disclosure of these issue has been credited to Bugtraq Security Systems <[email protected]>. |
| Vulnerable: |
Applied Watch Technologies Applied Watch Command Center 1.0 |
| Not Vulnerable: | |
Discussion
Applied Watch Command Center Authentication Bypass Vulnerability
A vulnerability has been identified in the system that may allow an attacker to bypass authentication to add attacker supplied IDS alerts and new user accounts in the console. Successful exploitation of these issues may allow an attacker to gain unauthorized access to a vulnerable system or conceal intrusion attempts.
Proof of concept exploits have been made available for this issue.
A vulnerability has been identified in the system that may allow an attacker to bypass authentication to add attacker supplied IDS alerts and new user accounts in the console. Successful exploitation of these issues may allow an attacker to gain unauthorized access to a vulnerable system or conceal intrusion attempts.
Proof of concept exploits have been made available for this issue.
Exploit / POC
Applied Watch Command Center Authentication Bypass Vulnerability
Exploit code has been provided.
Exploit code has been provided.
Solution / Fix
Applied Watch Command Center Authentication Bypass Vulnerability
Solution:
It has been reported that the vendor has released Applied Watch Command Center version 1.4.5 to address these issues. Users are advised to download the fixed version from the following web page:
https://my.appliedwatch.com
Solution:
It has been reported that the vendor has released Applied Watch Command Center version 1.4.5 to address these issues. Users are advised to download the fixed version from the following web page:
https://my.appliedwatch.com
References
Applied Watch Command Center Authentication Bypass Vulnerability
References:
References:
- Applied Watch Command Center Product page (Applied Watch Technologies)
- Applied Watch Response to Bugtraq.org post (Eric Hines
) - Re: Multiple Remote Issues in Applied Watch IDS Suite ("Chris Mann"
) - Re: Multiple Remote Issues in Applied Watch IDS Suite (advisory attached) ("Steven M. Christey"
)