Vulnerabilities > CVE-2014-8357 - Credentials Management vulnerability in Dasanzhone Znid 2426A Firmware

047910
CVSS 4.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
SINGLE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
dasanzhone
CWE-255
exploit available

Summary

backupsettings.html in the web administrative portal in Zhone zNID GPON 2426A before S3.0.501 places a session key in a URL, which allows remote attackers to obtain arbitrary user passwords via the sessionKey parameter in a getConfig action to backupsettings.conf.

Vulnerable Configurations

Part Description Count
OS
Dasanzhone
1
Hardware
Dasanzhone
1

Common Weakness Enumeration (CWE)

Exploit-Db

descriptionZHONE < S3.0.501 - Multiple Vulnerabilities. CVE-2014-8356,CVE-2014-8357,CVE-2014-9118. Remote exploit for hardware platform
fileexploits/hardware/remote/38453.txt
idEDB-ID:38453
last seen2016-02-04
modified2015-10-13
platformhardware
port
published2015-10-13
reporterLyon Yang
sourcehttps://www.exploit-db.com/download/38453/
titleZHONE < S3.0.501 - Multiple Vulnerabilities
typeremote

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/133921/VP-2015-002.txt
idPACKETSTORM:133921
last seen2016-12-05
published2015-10-12
reporterLyon Yang
sourcehttps://packetstormsecurity.com/files/133921/Zhone-Insecure-Reference-Password-Disclosure-Command-Injection.html
titleZhone Insecure Reference / Password Disclosure / Command Injection