SB2018102419 - Authentication bypass vulnerabilities in GAIN Electronic SAGA1-L
Published: October 24, 2018
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 3 vulnerabilities.
1) Authentication bypass (CVE-ID: CVE-2018-17903)
CWE-ID: CWE-294 - Authentication Bypass by Capture-replay
CVSSv4: 8.7 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows an adjacent attacker to bypass authentication on the target system.
The vulnerability exists due to authentication bypass by capture-replay. An adjacent attacker can conduct replay attack and command forge any commands.
2) Improper access control (CVE-ID: CVE-2018-20783)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 7.7 [CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows an adjacent attacker to bypass authentication on the target system.
The vulnerability exists due to improper access control. An adjacent attacker can force-pair the device without human interaction.
3) Improper authentication (CVE-ID: CVE-2018-17923)
CWE-ID: CWE-287 - Improper Authentication
CVSSv4: 5.4 [CVSS:4.0/AV:P/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a physical attacker to bypass authentication on the target system.
The vulnerability exists due to improper access control. An attacker with physical access to the product can reprogram it.
Remediation
Install update from vendor's website.