CVE-2018-20220

An issue was discovered on Teracue ENC-400 devices with firmware 2.56 and below. While the web interface requires authentication before it can be interacted with, a large portion of the HTTP endpoints are missing authentication. An attacker is able to view these pages before being authenticated, and some of these pages may disclose sensitive information.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:teracue:enc-400_hdmi_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:teracue:enc-400_hdmi:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:teracue:enc-400_hdmi2_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:teracue:enc-400_hdmi2:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:teracue:enc-400_hdsdi_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:teracue:enc-400_hdsdi:-:*:*:*:*:*:*:*

History

21 Nov 2024, 04:01

Type Values Removed Values Added
References () http://packetstormsecurity.com/files/151802/Teracue-ENC-400-Command-Injection-Missing-Authentication.html - Third Party Advisory, VDB Entry () http://packetstormsecurity.com/files/151802/Teracue-ENC-400-Command-Injection-Missing-Authentication.html - Third Party Advisory, VDB Entry
References () http://seclists.org/fulldisclosure/2019/Feb/48 - Mailing List, Third Party Advisory () http://seclists.org/fulldisclosure/2019/Feb/48 - Mailing List, Third Party Advisory
References () https://zxsecurity.co.nz/research.html - Not Applicable () https://zxsecurity.co.nz/research.html - Not Applicable

Information

Published : 2019-03-21 16:00

Updated : 2024-11-21 04:01


NVD link : CVE-2018-20220

Mitre link : CVE-2018-20220

CVE.ORG link : CVE-2018-20220


JSON object : View

Products Affected

teracue

  • enc-400_hdmi_firmware
  • enc-400_hdsdi
  • enc-400_hdmi2_firmware
  • enc-400_hdmi2
  • enc-400_hdsdi_firmware
  • enc-400_hdmi
CWE
CWE-306

Missing Authentication for Critical Function