Access Control Vulnerability in Genexis B.V. Router Configuration
CVE-2017-6094

9.8CRITICAL

Key Information:

Vendor

Genexis

Status
Vendor
CVE Published:
20 December 2017

What is CVE-2017-6094?

The vulnerability in Genexis B.V. GAPS allows attackers to exploit a flaw in the configuration settings process used by customer premises equipment (CPE) on the access network. By reverse engineering the firmware, the algorithm for generating a 'chk' value based on the MAC address becomes exposed. This enables the creation of forged 'chk' values corresponding to any MAC address, thereby granting unauthorized access to another subscriber's CPE configuration settings. These settings may include sensitive information, such as VoIP service credentials, significantly risking the privacy and security of users.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.