CVE-2003-1160
CVSS10.0
发布时间 :2003-10-30 00:00:00
修订时间 :2008-09-05 16:36:12
NMCOE    

[原文]FlexWATCH Network video server 132 allows remote attackers to bypass authentication and gain administrative privileges via an HTTP request to aindex.htm that contains double leading slashes (//).


[CNNVD]Seyeon FlexWATCH Network Video Server未授权管理访问漏洞(CNNVD-200310-088)

        
        Seyeon FlexWATCH Network Video Server是一款视频服务程序。
        Seyeon FlexWATCH网络视频服务程序存在访问验证错误,远程攻击者可以利用这个漏洞未授权访问管理员接口。
        攻击者只要提交包含两个"/"符号的管理接口URL请求,就可以绕过验证,直接进行管理员级别访问,这可导致用户帐户和系统配置被修改。
        

- CVSS (基础分值)

CVSS分值: 10 [严重(HIGH)]
机密性影响: COMPLETE [完全的信息泄露导致所有系统文件暴露]
完整性影响: COMPLETE [系统完整性可被完全破坏]
可用性影响: COMPLETE [可能导致系统完全宕机]
攻击复杂度: LOW [漏洞利用没有访问限制 ]
攻击向量: [--]
身份认证: NONE [漏洞利用无需身份认证]

- CPE (受影响的平台与产品)

cpe:/a:seyeon:flexwatch_network_video_server:2.2
cpe:/a:seyeon:flexwatch_network_video_server:model_132

- OVAL (用于检测的技术细节)

未找到相关OVAL定义

- 官方数据库链接

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1160
(官方数据源) MITRE
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2003-1160
(官方数据源) NVD
http://www.cnnvd.org.cn/vulnerability/show/cv_cnnvdid/CNNVD-200310-088
(官方数据源) CNNVD

- 其它链接及资源

http://www.osvdb.org/2842
(VENDOR_ADVISORY)  OSVDB  2842
http://xforce.iss.net/xforce/xfdb/13567
(VENDOR_ADVISORY)  XF  flexwatch-slash-admin-access(13567)
http://www.securityfocus.com/bid/8942
(UNKNOWN)  BID  8942
http://securitytracker.com/id?1008049
(UNKNOWN)  SECTRACK  1008049
http://secunia.com/advisories/10132
(VENDOR_ADVISORY)  SECUNIA  10132
http://packetstormsecurity.nl/0310-exploits/FlexWATCH.txt
(UNKNOWN)  MISC  http://packetstormsecurity.nl/0310-exploits/FlexWATCH.txt

- 漏洞信息

Seyeon FlexWATCH Network Video Server未授权管理访问漏洞
危急 访问验证错误
2003-10-30 00:00:00 2005-10-20 00:00:00
远程  
        
        Seyeon FlexWATCH Network Video Server是一款视频服务程序。
        Seyeon FlexWATCH网络视频服务程序存在访问验证错误,远程攻击者可以利用这个漏洞未授权访问管理员接口。
        攻击者只要提交包含两个"/"符号的管理接口URL请求,就可以绕过验证,直接进行管理员级别访问,这可导致用户帐户和系统配置被修改。
        

- 公告与补丁

        厂商补丁:
        Seyeon
        ------
        目前厂商还没有提供补丁或者升级程序,我们建议使用此软件的用户随时关注厂商的主页以获取最新版本:
        
        http://www.flexwatch.com/products/fw_nvs.asp

- 漏洞信息 (23317)

Seyeon FlexWATCH Network Video Server 2.2 Unauthorized Administrative Access Vulnerability (EDBID:23317)
hardware remote
2003-10-31 Verified
0 slaizer
N/A [点击下载]
source: http://www.securityfocus.com/bid/8942/info

It has been reported that FlexWATCH Network Video Server may be prone to an access validation error that may allow a remote attacker to gain administrative access to the system. The problem is reported to present itself when an attacker attempts to access the administrative interface using a specially crafted URL containing two slash '/' characters.

Successful exploitation of this issue may allow a remote attacker to gain administrator level privileges to the server. This may lead to user accounts and system configuration modifications.

FlexWATCH Network Video Server Model 132 has been reported to be prone to this issue, however other versions may be affected as well.

http://www.example.com//admin/aindex.htm		

- 漏洞信息

2842
Sayeon FlexWATCH Double-Slash Authentication Bypass

- 漏洞描述

FlexWATCH Network Video Server contains a flaw that may allow a malicious user to bypass the authentication and gain access to the embedded web server. The issue is triggered when two forward-slash characters are used when accessing the administrative webpage. It is possible that the flaw may allow an authorize user to reconfigure the server, manage user accounts, and view the video feeds.

- 时间线

2003-10-26 2003-10-26
2003-10-26 Unknow

- 解决方案

The vendor has released firmware version 2.2 to fix this particular vulnerability, however another method of bypassing authentication was discovered almost immediately afterwards. As of the time of this writing (January 3rd, 2004) there is no available patch from the vendor which adequately protects this server. If the security of this system is critical, it should be placed behind a packet filter or firewall.

- 相关参考

- 漏洞作者

Unknown or Incomplete
 

 

关于SCAP中文社区

SCAP中文社区是国内第一个以SCAP为主题的中文开放社区。了解更多信息,请查阅[关于本站]

版权声明

CVE/CWE/OVAL均为MITRE公司的注册商标,它们的官方数据源均保存在MITRE公司的相关网站