CVE-2015-7285

CSL DualCom GPRS CS2300-R devices with firmware 1.25 through 3.53 do not require authentication from Alarm Receiving Center (ARC) servers, which allows man-in-the-middle attackers to bypass intended access restrictions via a spoofed HSxx response.
References
Link Resource
http://cybergibbons.com/?p=2844 Exploit
http://www.kb.cert.org/vuls/id/428280 Third Party Advisory US Government Resource
http://www.kb.cert.org/vuls/id/BLUU-A3NQAL Third Party Advisory US Government Resource
http://cybergibbons.com/?p=2844 Exploit
http://www.kb.cert.org/vuls/id/428280 Third Party Advisory US Government Resource
http://www.kb.cert.org/vuls/id/BLUU-A3NQAL Third Party Advisory US Government Resource
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:o:csl_dualcom:gprs_cs2300-r_firmware:1.25:*:*:*:*:*:*:*
cpe:2.3:o:csl_dualcom:gprs_cs2300-r_firmware:3.53:*:*:*:*:*:*:*
cpe:2.3:h:csl_dualcom:gprs:cs2300-r:*:*:*:*:*:*:*

History

21 Nov 2024, 02:36

Type Values Removed Values Added
References () http://cybergibbons.com/?p=2844 - Exploit () http://cybergibbons.com/?p=2844 - Exploit
References () http://www.kb.cert.org/vuls/id/428280 - Third Party Advisory, US Government Resource () http://www.kb.cert.org/vuls/id/428280 - Third Party Advisory, US Government Resource
References () http://www.kb.cert.org/vuls/id/BLUU-A3NQAL - Third Party Advisory, US Government Resource () http://www.kb.cert.org/vuls/id/BLUU-A3NQAL - Third Party Advisory, US Government Resource

Information

Published : 2015-11-25 04:59

Updated : 2024-11-21 02:36


NVD link : CVE-2015-7285

Mitre link : CVE-2015-7285

CVE.ORG link : CVE-2015-7285


JSON object : View

Products Affected

csl_dualcom

  • gprs
  • gprs_cs2300-r_firmware
CWE
CWE-287

Improper Authentication