CVE-2018-20219

An issue was discovered on Teracue ENC-400 devices with firmware 2.56 and below. After successful authentication, the device sends an authentication cookie to the end user such that they can access the devices web administration panel. This token is hard-coded to a string in the source code (/usr/share/www/check.lp file). By setting this cookie in a browser, an attacker is able to maintain access to every ENC-400 device without knowing the password, which results in authentication bypass. Even if a user changes the password on the device, this token is static and unchanged.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:teracue:enc-400_hdmi_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:teracue:enc-400_hdmi:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:teracue:enc-400_hdmi2_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:teracue:enc-400_hdmi2:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:teracue:enc-400_hdsdi_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:teracue:enc-400_hdsdi:-:*:*:*:*:*:*:*

History

21 Nov 2024, 04:01

Type Values Removed Values Added
References () http://packetstormsecurity.com/files/151802/Teracue-ENC-400-Command-Injection-Missing-Authentication.html - Third Party Advisory, VDB Entry () http://packetstormsecurity.com/files/151802/Teracue-ENC-400-Command-Injection-Missing-Authentication.html - Third Party Advisory, VDB Entry
References () http://seclists.org/fulldisclosure/2019/Feb/48 - Mailing List, Third Party Advisory () http://seclists.org/fulldisclosure/2019/Feb/48 - Mailing List, Third Party Advisory
References () https://zxsecurity.co.nz/research.html - Not Applicable () https://zxsecurity.co.nz/research.html - Not Applicable

Information

Published : 2019-03-21 16:00

Updated : 2024-11-21 04:01


NVD link : CVE-2018-20219

Mitre link : CVE-2018-20219

CVE.ORG link : CVE-2018-20219


JSON object : View

Products Affected

teracue

  • enc-400_hdmi_firmware
  • enc-400_hdsdi
  • enc-400_hdmi2_firmware
  • enc-400_hdmi2
  • enc-400_hdsdi_firmware
  • enc-400_hdmi
CWE
CWE-798

Use of Hard-coded Credentials