vendor:
UNIVERGE® SV9100
by:
Gjoko 'LiquidWorm' Krstic
8.8
CVSS
HIGH
Disclosing default credentials with weak password policy
259
CWE
Product Name: UNIVERGE® SV9100
Affected Version From: WebPro <=10.00
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: h:nec:univerge_sv9100:10.0
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Henry/1.1, NEC-i SV8100-NA 08.00/2.1, NEC SV9100-GE 07.00.52/2.1
2017
NEC Univerge SV9100/SV8100 WebPro 10.0 Remote Configuration Download
The gzipped telephone system configuration file 'config.gz' or 'config.pcpx' that contains the unencrypted data file 'conf.pcpn', can be downloaded by an attacker from the root directory if previously generated by a privileged user. Attacker can also sniff the network and hijack the session id which resides in a GET request to further generate the config file. The sessionid can also be brute-forced because of its predictability containing 5-digit number. This will enable the attacker to disclose sensitive information and help her in authentication bypass, privilege escalation, system access and denial of service via config modification.
Mitigation:
Enforce strong password policy and restrict access to the root directory.