Missing Authentication for Critical Function in 3D-A1000 Dimensioning System - CVE-2022-1368

 

Missing Authentication for Critical Function in 3D-A1000 Dimensioning System - CVE-2022-1368

Published: September 7, 2022


Vulnerability identifier: #VU67057
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-1368
CWE-ID: CWE-306
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to escalate privileges on the system.

The vulnerability exists due to missing authentication for critical function. A remote attacker can change the operator account password via webserver commands by monitoring web socket communications from an unauthenticated session and gain elevated privileges on the target system.


Affected software

3D-A1000 Dimensioning System

How to mitigate CVE-2022-1368

Install updates from vendor's website.

3D-A1000 Dimensioning System - update to 1.2 PR2

External References

Related Security Bulletins