vendor:
Solar-Log 500
by:
Luca.Chiou
7.5
CVSS
HIGH
Incorrect Access Control
287
CWE
Product Name: Solar-Log 500
Affected Version From: Solar-Log 500 all versions prior to 2.8.2 Build 52 - 23.04.2013
Affected Version To: Solar-Log 500 all versions prior to 2.8.2 Build 52 - 23.04.2013
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Proprietary devices
2021
Solar-Log 500 2.8.2 – Incorrect Access Control
The web administration server for Solar-Log 500 all versions prior to 2.8.2 Build 52 does not require authentication, which allows arbitrary remote attackers to gain administrative privileges by connecting to the server. As a result, the attacker can modify configuration files and change the system status.
Mitigation:
Authentication should be required for the web administration server for Solar-Log 500.