Authentication bypass using an alternate path or channel in TONE Family - #VU75147

 

Authentication bypass using an alternate path or channel in TONE Family - #VU75147

Published: April 17, 2023


Vulnerability identifier: #VU75147
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-288
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to an authentication bypass using an alternate path within the API server. A remote attacker can login to the management console of the affected service and gain access to sensitive information.


Affected software

TONE Family

Remediation

Install updates from vendor's website.


External References

Related Security Bulletins