본문 바로가기

취약점 정보1

Amtelco miSecureMessages app lacks authentication

728x90

Overview

Amtelco miSecureMessages lacks authentication for access to user messages. (CWE-287)

Description

Amtelco miSecureMessages lacks authentication for access to user messages. The miSecureMessages app has been reported to lack authentication and session management. An attacker only needs to provide a contactID and valid license key in their xml request to the server to access any user's messages.

Impact

A remote unauthenticated attacker may be able to read the messages of all users by iterating through all possible contactIDs.

Solution

We are currently unaware of a practical solution to this problem.

Vendor Information (Learn More)

VendorStatusDate NotifiedDate Updated
AmtelcoAffected-11 Apr 2014

If you are a vendor and your product is affected, let us know.

CVSS Metrics (Learn More)

GroupScoreVector
Base7.8AV:N/AC:L/Au:N/C:C/I:N/A:N
Temporal6.3E:POC/RL:U/RC:UC
Environmental4.7CDP:ND/TD:M/CR:ND/IR:ND/AR:ND

References

Credit

Thanks to Jared Bird for reporting this vulnerability.

This document was written by Jared Allar.

Other Information

  • CVE IDs: CVE-2014-0357
  • Date Public: 11 4월 2014
  • Date First Published: 11 4월 2014
  • Date Last Updated: 11 4월 2014
  • Document Revision: 7
728x90