CVE-2015-0932

The ANTlabs InnGate firmware on IG 3100, IG 3101, InnGate 3.00 E, InnGate 3.01 E, InnGate 3.02 E, InnGate 3.10 E, InnGate 3.01 G, and InnGate 3.10 G devices does not require authentication for rsync sessions, which allows remote attackers to read or write to arbitrary files via TCP traffic on port 873.
Configurations

Configuration 1 (hide)

OR cpe:2.3:h:antlabs:inngate_ig_3.00_e:*:*:*:*:*:*:*:*
cpe:2.3:h:antlabs:inngate_ig_3.01_e:*:*:*:*:*:*:*:*
cpe:2.3:h:antlabs:inngate_ig_3.02_e:*:*:*:*:*:*:*:*
cpe:2.3:h:antlabs:inngate_ig_3.10_e:*:*:*:*:*:*:*:*
cpe:2.3:h:antlabs:inngate_ig_3.10_g:*:*:*:*:*:*:*:*
cpe:2.3:h:antlabs:inngate_ig_3100:*:*:*:*:*:*:*:*
cpe:2.3:h:antlabs:inngate_ig_3101:*:*:*:*:*:*:*:*

History

21 Nov 2024, 02:24

Type Values Removed Values Added
References () http://blog.cylance.com/spear-team-cve-2015-0932 - Exploit () http://blog.cylance.com/spear-team-cve-2015-0932 - Exploit
References () http://www.antlabs.com/index.php?option=com_content&view=article&id=195:rsync-remote-file-system-access-vulnerability-cve-2015-0932&catid=54:advisories&Itemid=133 - Patch, Vendor Advisory () http://www.antlabs.com/index.php?option=com_content&view=article&id=195:rsync-remote-file-system-access-vulnerability-cve-2015-0932&catid=54:advisories&Itemid=133 - Patch, Vendor Advisory
References () http://www.kb.cert.org/vuls/id/930956 - Third Party Advisory, US Government Resource () http://www.kb.cert.org/vuls/id/930956 - Third Party Advisory, US Government Resource
References () http://www.wired.com/2015/03/big-vulnerability-hotel-wi-fi-router-puts-guests-risk/ - () http://www.wired.com/2015/03/big-vulnerability-hotel-wi-fi-router-puts-guests-risk/ -

Information

Published : 2015-04-05 01:59

Updated : 2024-11-21 02:24


NVD link : CVE-2015-0932

Mitre link : CVE-2015-0932

CVE.ORG link : CVE-2015-0932


JSON object : View

Products Affected

antlabs

  • inngate_ig_3.00_e
  • inngate_ig_3.10_g
  • inngate_ig_3.02_e
  • inngate_ig_3.01_e
  • inngate_ig_3100
  • inngate_ig_3.10_e
  • inngate_ig_3101
CWE
CWE-264

Permissions, Privileges, and Access Controls