Vulnerabilities > CVE-2014-2046 - Cryptographic Issues vulnerability in Broadcom Pipa C211 and Pipa C211 web Interface

047910
CVSS 0.0 - NONE
Attack vector
UNKNOWN
Attack complexity
UNKNOWN
Privileges required
UNKNOWN
Confidentiality impact
UNKNOWN
Integrity impact
UNKNOWN
Availability impact
UNKNOWN
broadcom
CWE-310
exploit available

Summary

cgi-bin/rpcBridge in the web interface 1.1 on Broadcom Ltd PIPA C211 rev2 does not properly restrict access, which allows remote attackers to (1) obtain credentials and other sensitive information via a certain request to the config.getValuesHashExcludePaths method or (2) modify the firmware via unspecified vectors.

Vulnerable Configurations

Part Description Count
Application
Broadcom
1
Hardware
Broadcom
1

Common Weakness Enumeration (CWE)

Common Attack Pattern Enumeration and Classification (CAPEC)

  • Signature Spoofing by Key Recreation
    An attacker obtains an authoritative or reputable signer's private signature key by exploiting a cryptographic weakness in the signature algorithm or pseudorandom number generation and then uses this key to forge signatures from the original signer to mislead a victim into performing actions that benefit the attacker.

Exploit-Db

descriptionBroadcom PIPA C211 - Sensitive Information Disclosure. CVE-2014-2046. Webapps exploit for hardware platform
idEDB-ID:33353
last seen2016-02-03
modified2014-05-14
published2014-05-14
reporterPortcullis
sourcehttps://www.exploit-db.com/download/33353/
titleBroadcom PIPA C211 - Sensitive Information Disclosure

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/126601/broadcompipa-bypass.txt
idPACKETSTORM:126601
last seen2016-12-05
published2014-05-13
reporterJerzy Kramarz
sourcehttps://packetstormsecurity.com/files/126601/Broadcom-PIPA-C211-Information-Disclosure.html
titleBroadcom PIPA C211 Information Disclosure

Seebug

bulletinFamilyexploit
descriptionNo description provided by source.
idSSV:86576
last seen2017-11-19
modified2014-07-01
published2014-07-01
reporterRoot
sourcehttps://www.seebug.org/vuldb/ssvid-86576
titleBroadcom PIPA C211 - Sensitive Information Disclosure