CVE Vulnerabilities

CVE-2019-12254

Improper Authentication

Published: May 06, 2022 | Modified: May 16, 2022
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

In multiple Tecson Tankspion and GOKs SmartBox 4 products the affected application doesnt properly restrict access to an endpoint that is responsible for saving settings, to a unauthenticated user with limited access rights. Based on the lack of adequately implemented access-control rules, by accessing a specific uniform resource locator (URL) on the web server, a malicious user is able to change the application settings without authenticating at all, which violates originally laid ACL rules.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Smartbox_4_lan_firmware Gok * *

Potential Mitigations

References