vendor:
CloudGate M2M gateway
by:
Gjoko 'LiquidWorm' Krstic
7,5
CVSS
HIGH
Insecure Direct Object References
639
CWE
Product Name: CloudGate M2M gateway
Affected Version From: CG0192-11897
Affected Version To: CG0192-11897
Patch Exists: YES
Related CWE: N/A
CPE: a:option:cloudgate
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: lighttpd 1.4.39, firmware 2.62.4
2016
Option CloudGate Insecure Direct Object References Authorization Bypass
Insecure Direct Object References occur when an application provides direct access to objects based on user-supplied input. As a result of this vulnerability attackers can bypass authorization and access resources and functionalities in the system directly, for example APIs, files, upload utilities, device settings, etc.
Mitigation:
Ensure that user-supplied input is not used to access objects directly.