In the web-panel in IQrouter through 3.3.1, remote attackers can read system logs because of Incorrect Access Control. Note: The vendor…
mitre·CWE-532·Published 2020-04-21
In the web-panel in IQrouter through 3.3.1, remote attackers can read system logs because of Incorrect Access Control. Note: The vendor claims that this vulnerability can only occur on a brand-new network that, after initiating the forced initial configuration (which has a required step for setting a secure password on the system), makes this CVE invalid. This vulnerability is “true for any unconfigured release of OpenWRT, and true of many other new Linux distros prior to being configured for the first time”
In the web-panel in IQrouter through 3.3.1, remote attackers can read system logs because of Incorrect Access Control. Note: The vendor claims that this vulnerability can only occur on a brand-new network that, after initiating the forced initial configuration (which has a required step for setting a secure password on the system), makes this CVE invalid. This vulnerability is “true for any unconfigured release of OpenWRT, and true of many other new Linux distros prior to being configured for the first time”
** EN DISPUTA ** En el panel web en IQrouter versiones hasta la versión 3.3.1, los atacantes remotos pueden leer los registros del sistema debido a un Control de Acceso Incorrecto. Nota: El vendedor afirma que esta vulnerabilidad sólo puede ocurrir en una red nueva que, después de iniciar la configuración inicial forzada (que tiene un paso requerido para establecer una contraseña segura en el sistema), hace que este CVE no sea válido. Esta vulnerabilidad es "verdadera para cualquier versión no configurada de OpenWRT, y verdadera para muchas otras nuevas distribuciones de Linux antes de ser configuradas por primera vez"
| Version | Type | Source | Base | Exp | Impact | Vector |
|---|---|---|---|---|---|---|
| 2.0 | Primary | NVD | 5.0 | 10.0 | 2.9 | AV:N/AC:L/Au:N/C:P/I:N/A:N |
| 3.1 | Primary | NVD | 7.5 | 3.9 | 3.6 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |