Authentication Vulnerability in Riello NetMan 204 and 15-2
CVE-2017-6900

9.8CRITICAL

Key Information:

Vendor

Riello-ups

Vendor
CVE Published:
3 July 2019

What is CVE-2017-6900?

An authentication vulnerability exists in Riello NetMan 204 versions 14-2 and 15-2 due to improper handling of variables in the login script and the wrongpass Python script. The failure to enclose variables $VAL0 and $VAL1 in quotes can lead to Bash command injection, while poor error handling allows an attacker to log in as an administrator by exploiting a specific username input. This vulnerability can be further exacerbated by the fact that login.cgi accepts the username as a GET parameter, enabling remote login via crafted URIs. The potential consequences include enabling telnet/SSH services and resetting local user credentials, which pose significant security risks.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2017-6900 : Authentication Vulnerability in Riello NetMan 204 and 15-2