vendor:
InfraPower Manager PPS-02-S
by:
Gjoko 'LiquidWorm' Krstic
7,5
CVSS
HIGH
Authentication Bypass
287
CWE
Product Name: InfraPower Manager PPS-02-S
Affected Version From: Q213V1 (Firmware: V2395S)
Affected Version To: Q216V3 (Firmware: IPD-02-FW-v03)
Patch Exists: YES
Related CWE: N/A
CPE: austin-hughes.com:infrapower_manager_pps-02-s:q213v1
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux 2.6.28 (armv5tel), lighttpd/1.4.30-devel-1321, PHP/5.3.9, SQLite/3.7.10
2016
InfraPower PPS-02-S Q213V1 Authentication Bypass Vulnerability
The device does not properly perform authentication, allowing it to be bypassed through cookie manipulation. The vulnerable function checkLogin() in 'Function.php' checks only if the 'Login' Cookie is empty or not, allowing easy bypass of the user security mechanisms.
Mitigation:
Upgrade to the latest version of the InfraPower Manager PPS-02-S.