b374k
v10
today : | at : | safemode : ON
> / home / facebook / twitter / exit /
name author perms com modified label

SNMP Flaw Affects Several Online Devices Asylum rwxr-xr-x 0 6:05 PM

Filename SNMP Flaw Affects Several Online Devices
Permission rw-r--r--
Author Asylum
Date and Time 6:05 PM
Label
Action
(pc- Google Images)
A severe security flaw in the implementation of the SNMP (Simple Network Management) Protocol allows an attacker to take over at least 78 cable modem models.

SNMP is used for automated network device identification, monitoring and remote configuration. It is supported and enabled by default in many devices, including servers, printers, networking hubs, switches and routers.

The problem, dubbed StringBleed and tracked as CVE 2017-5135, was reported by the security researchers Ezequiel Fernandez and Bertin Bervis.

The SNMP protocol supports three methods for client authentication and to authenticate requests on remote SNMP devices, two of them are affected by the authentication bypass issue.

Versions 1 and 2 of the SNMP protocol don't have strong authentication to begin with. They provide either read-only or write access to a device's configuration through passwords called community strings.

The StringBleed vulnerability is an Incorrect Access Control issue, remote attackers could exploit the issue to execute code on the vulnerable devices and gain “full read/write remote permissions using any string/integer value.”

“In few words, we discovered the following: you can use any value string or integer in order to authenticate the SNMP agent successfully in some specific devices, but the worse thing here is : you have full read/write remote permissions using any string/integer value.” said the researchers.


via E Hacking News - Latest Hacker News and IT Security News SNMP Flaw Affects Several Online Devices http://ift.tt/2pzMQMI

0 comments:

Post a Comment

 

Jayalah Indonesiaku © 2010 Hacker News
VB (Vio b374k) Template design by p4r46hcyb3rn3t