Privilege escalation vulnerability
SEC Consult identified a privilege escalation vulnerability in the MICROSENS Web Manager in the course of a very limited infrastructure audit. The Web Manager can be used with read only permission to check the configuration on the device (e.g. VLANs, Port status). Additionally the Web Manager can be used with read and write permission to configure the device. Using the identified vulnerability a low privileged user having read only permission can elevate his privileges to contain read and write permissions. The login attempt is checked through a CGI binary, but the response of the binary is validated at the client side via JavaScript. An attacker can manipulate the response of the CGI binary and can bypass the client side validation.