Moxa AWK-3131A Web Application onekey Information Disclosure Vulnerability(CVE-2016-0241)

基本字段

漏洞编号:
SSV-96542
披露/发现时间:
2016-11-18
提交时间:
2017-09-20
漏洞等级:
漏洞类别:
信息泄漏
影响组件:
Moxa AWK-3131A
漏洞作者:
Patrick DeSantis of Cisco Talos
提交者:
Knownsec
CVE-ID:
CVE-2016-0241
CNNVD-ID:
补充
CNVD-ID:
补充
ZoomEye Dork:
补充

来源

漏洞详情

贡献者 共获得  0KB

Summary

An exploitable information disclosure vulnerability exists in the Web Application functionality of Moxa AWK-3131A Wireless Access Point. Retrieving a series of URLs without authentication can reveal sensitive configuration and system information to an attacker.

Tested Versions

Moxa AWK-3131A Series Industrial IEEE 802.11a/b/g/n wireless AP/bridge/client 1.1

Product URLs

http://www.moxa.com/product/AWK-3131A.htm

CVSSv3 Score

7.5 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

An exploitable information disclosure vulnerability exists in the Web Application functionality of Moxa AWK-3131A Series Industrial IEEE 802.11a/b/g/n wireless AP/bridge/client. Retrieving a series of URLs without authentication can reveal sensitive configuration and system information to an attacker.

Specifically, an unauthenticated attacker can visit http:///makeonekey.gz and then http:///getonekey.gz to obtain compressed file which contains systemlog.log, config.ini, and the system_status folder. These files contain sensitive information, including encoded credentials for system services and wireless interfaces.

Exploit Proof-of-Concept (optional)

First

http://<Device IP>/makeonekey.gz

Then

http://<Device IP>/getonekey.gz

Mitigation (optional)

To significantly mitigate risk of exploitation, disable the web application before the device is deployed.

Timeline

  • 2016-11-18 - Vendor Disclosure
  • 2017-04-10 - Public Release

CREDIT

  • Discovered by Patrick DeSantis of Cisco Talos.
共 0  兑换了

PoC (非 pocsuite 插件)

贡献者 Knownsec 共获得   0KB
1
2
3
4
5
First
http://<Device IP>/makeonekey.gz
Then
http://<Device IP>/getonekey.gz
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX

共 0 兑换

参考链接

解决方案

临时解决方案

暂无临时解决方案

官方解决方案

暂无官方解决方案

防护方案

暂无防护方案

人气 1421
评论前需绑定手机 现在绑定

暂无评论

※本站提供的任何内容、代码与服务仅供学习,请勿用于非法用途,否则后果自负