vendor:
netBooter NP-02x/NP-08x
by:
Gjoko 'LiquidWorm' Krstic
7.5
CVSS
HIGH
Authentication Bypass
287
CWE
Product Name: netBooter NP-02x/NP-08x
Affected Version From: NP-0201D (ver 6.8C)
Affected Version To: NP-08 (ver 6.10)
Patch Exists: YES
Related CWE: N/A
CPE: h:synaccess:netbooter_np-02x_np-08x
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Synaccess server
2018
Synaccess netBooter NP-02x/NP-08x 6.8 Authentication Bypass
netBooter suffers from an authentication bypass vulnerability due to missing control check when calling webNewAcct.cgi script while creating users. This allows an unauthenticated attacker to create admin user account and bypass authentication giving her the power to turn off a power supply to a resource.
Mitigation:
Ensure that authentication checks are in place when creating user accounts.