SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2018-20219

This token is hard-coded to a string in the source code (/usr/share/www/check.lp file).

HIGH 8.1EPSS 14.6%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 14.6%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.

Description

An issue was discovered on Teracue ENC-400 devices with firmware 2.56 and below. After successful authentication, the device sends an authentication cookie to the end user such that they can access the devices web administration panel. This token is hard-coded to a string in the source code (/usr/share/www/check.lp file). By setting this cookie in a browser, an attacker is able to maintain access to every ENC-400 device without knowing the password, which results in authentication bypass. Even if a user changes the password on the device, this token is static and unchanged.

CVSS 3.0
8.1 HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
14.55% probability · 96th percentile
CISA KEV
Not listed
Weakness
CWE-798
Affected
teracue/enc-400 hdmi firmware · teracue/enc-400 hdmi2 firmware · teracue/enc-400 hdsdi firmware
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.