Power Distribution Units running on Powertek firmware (multiple brands) before 3.30.30 have an insecure permissions setting on the user.token field that is accessible to everyone through the /cgi/get_param.cgi HTTP API. This leads to disclosing active session ids of currently logged-in administrators. The session id can then be reused to act as the administrator, allowing reading of the cleartext password, or reconfiguring the device.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Powertekpdus
Subscribe
|
Basic Pdu
Subscribe
Basic Pdu Firmware
Subscribe
Piml Pdu
Subscribe
Piml Pdu Firmware
Subscribe
Pm Pdu
Subscribe
Pm Pdu Firmware
Subscribe
Smart Pim
Subscribe
Smart Pim Firmware
Subscribe
Smart Pom
Subscribe
Smart Pom Firmware
Subscribe
Smart Poms
Subscribe
Smart Poms Firmware
Subscribe
Smart Pos
Subscribe
Smart Pos Firmware
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-36219 | Power Distribution Units running on Powertek firmware (multiple brands) before 3.30.30 have an insecure permissions setting on the user.token field that is accessible to everyone through the /cgi/get_param.cgi HTTP API. This leads to disclosing active session ids of currently logged-in administrators. The session id can then be reused to act as the administrator, allowing reading of the cleartext password, or reconfiguring the device. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://gynvael.coldwind.pl/?lang=en&id=748 |
|
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-03T08:01:20.393Z
Reserved: 2022-06-13T00:00:00
Link: CVE-2022-33175
No data.
Status : Modified
Published: 2022-06-13T18:15:10.283
Modified: 2024-11-21T07:07:39.347
Link: CVE-2022-33175
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD