SB2019070505 - Use of hard-coded credentials in WolfVision Cynap



SB2019070505 - Use of hard-coded credentials in WolfVision Cynap

Published: July 5, 2019 Updated: July 17, 2020

Security Bulletin ID SB2019070505
Severity
High
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Use of hard-coded credentials (CVE-ID: CVE-2019-13352)

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

WolfVision Cynap before 1.30j uses a static, hard-coded cryptographic secret for generating support PINs for the 'forgot password' feature. By knowing this static secret and the corresponding algorithm for calculating support PINs, an attacker can reset the ADMIN password and thus gain remote access.


Remediation

Install update from vendor's website.