vendor:
Axis StorPoint CD and Axis StorPoint CD/T
by:
SecurityFocus
7.5
CVSS
HIGH
Authentication Bypass
287
CWE
Product Name: Axis StorPoint CD and Axis StorPoint CD/T
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2002
Axis StorPoint CD and Axis StorPoint CD/T Authentication Bypass Vulnerability
Axis StorPoint CD and Axis StorPoint CD/T are CD ROM servers (actual hardware units)sold by Axis Communications. Both of these appliances support remote management via SNMP MIB-II and private enterprise MIB as well as from the web via a system-supplied webserver. In regards to the web based administration, users can completely bypass authentication (username and password) by using a specified URL. The actual login page is located at: http://server/config/html/cnf_gi.htm. However, by using http://server/cd/../config/html/cnf_gi.htm, a user side steps the login page and gains administrative access to the appliance.
Mitigation:
Ensure that authentication is properly enforced on the web-based administration interface.