ID:5856 - Exploit for Improper Authentication in CBAS Web - CVE-2019-10853

 
Main Vulnerability Database Exploits ID:5856 - Exploit for Improper Authentication in CBAS Web - CVE-2019-10853

ID:5856 - Exploit for Improper Authentication in CBAS Web - CVE-2019-10853

Published: June 17, 2021


Vulnerability identifier: #VU18653
Vulnerability risk: High
CVE-ID: CVE-2019-10853
CWE-ID: CWE-287
Exploitation vector: Remote access
Vulnerable software:
CBAS Web

Link to public exploit:


Vulnerability description

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to an error in the AggregatePost function when calling agg_postaction in auth.php script. A remote attacker can send a specially crafted parameters to a function, bypass authentication process and gain unauthorized access to full control of the device.


Remediation

Install updates from vendor's website.