vendor:
Hawkeye-G
by:
John Page (hyp3rlinx)
8.8
CVSS
HIGH
CSRF
352
CWE
Product Name: Hawkeye-G
Affected Version From: v3.0.1.4912
Affected Version To: v3.0.1.4912
Patch Exists: YES
Related CWE: CVE-2015-2878
CPE: a:hexis_cyber_solutions:hawkeye-g
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 7 SP1
2015
CSRF, Network Threat Appliance IDS / IPS
Multiple CSRF(s) Vulnerabilities: 1- CSRF Add arbitrary accounts to system vulnerable URL: https://localhost:8443/interface/rest/accounts/json vulnerable POST parameter: 'name' 2- CSRF modification of network sensor settings a) Turn off 'Url matching' Sensor b) Turn off 'DNS Inject' Sensor c) Turn off 'IP Redirect' Sensor vulnerable URL: https://localhost:8443/interface/rest/dpi/setEnabled/1 vulnerable POST parameters: 'url_match' 'dns_inject' 'ip_redirect' 3- CSRF whitelisting of malware MD5 hash IDs vulnerable URL: https://localhost:8443/interface/rest/md5-threats/whitelist vulnerable POST parameter 'id'
Mitigation:
Ensure that all user input is validated and sanitized before being used in any application. Implement CSRF tokens to verify the authenticity of requests.