The ANTlabs InnGate firmware on IG 3100, IG 3101, InnGate 3.00 E, InnGate 3.01 E, InnGate 3.02 E, InnGate 3.10 E, InnGate 3.01 G, and InnGate 3.10 G devices does not require authentication for rsync sessions, which allows remote attackers to read or write to arbitrary files via TCP traffic on port 873.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://www.wired.com/2015/03/big-vulnerability-hotel-wi-fi-router-puts-guests-risk/ | |
http://www.kb.cert.org/vuls/id/930956 | third party advisory us government resource |
http://blog.cylance.com/spear-team-cve-2015-0932 | exploit |
http://www.antlabs.com/index.php?option=com_content&view=article&id=195:rsync-remote-file-system-access-vulnerability-cve-2015-0932&catid=54:advisories&Itemid=133 | patch vendor advisory |