vendor:
Conceptronic CH3ENAS, Conceptronic CH3HNAS, Sitecom MD-253 and MD254
by:
Alcyon
7,5
CVSS
HIGH
Password disclosure Vulnerability
N/A
CWE
Product Name: Conceptronic CH3ENAS, Conceptronic CH3HNAS, Sitecom MD-253 and MD254
Affected Version From: 3.0.8
Affected Version To: 2.4.11
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2012
Conceptronic Grab’n’Go and Sitecom Storage Center – Password disclosure Vulnerability – Security Advisory AA-002
An attacker can harvest administrator credentials and log into the web management UI. Possibilities include but are not limited to reading and writing files stored on the device and altering the device’s configuration. This means an attacker could steal sensitive data stored on the device, leverage the device to drop and/or host malware, abuse the device to send spam through the victim’s Internet connection, and use the device as a pivot point to access locally connected systems or launch attacks directed to other systems.
Mitigation:
Update the firmware of the device to the latest version available.