The login interface on TNLSoftSolutions Sentry Vision 3.x devices provides password disclosure by reading an "if(pwd ==" line in the HTML source code. This means, in effect, that authentication occurs only on the client side.
References
Link | Resource |
---|---|
https://www.youtube.com/watch?v=pLMH9vGPRCo | Third Party Advisory |
https://gist.github.com/pabloonicarres/c2c284ca7b025d629da39087445ed15d#file-sentryvision_authentication_bypass-sh | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2018-03-29 09:29
Updated : 2019-10-02 17:03
NVD link : CVE-2018-9031
Mitre link : CVE-2018-9031
JSON object : View
CWE
CWE-522
Insufficiently Protected Credentials
Products Affected
tnlsoftsolutions
- sentry_vision