Support Us — Your donation helps us keep running

Goal: 1000 CNY,Raised: 1000 CNY

100.0%
Get alerts for future matching vulnerabilitiesLog in to subscribe
I. Basic Information for CVE-2019-12254
Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
TECSON/GOK: Improper Authentication and Access Control on multiple devices
Source: NVD (National Vulnerability Database)
Vulnerability Description
In multiple Tecson Tankspion and GOKs SmartBox 4 products the affected application doesn't properly restrict access to an endpoint that is responsible for saving settings, to a unauthenticated user with limited access rights. Based on the lack of adequately implemented access-control rules, by accessing a specific uniform resource locator (URL) on the web server, a malicious user is able to change the application settings without authenticating at all, which violates originally laid ACL rules.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: NVD (National Vulnerability Database)
Vulnerability Type
认证机制不恰当
Source: NVD (National Vulnerability Database)
Vulnerability Title
TECSON/GOK SmartBox 授权问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
TECSON/GOK SmartBox是德国TECSON/GOK公司的一系列电子油箱管理系统。 TECSON/GOK SmartBox 系列4款产品存在授权问题漏洞,该漏洞源于缺乏充分实施的访问控制规则,恶意用户通过访问 Web 服务器上的特定统一资源定位器 (URL) 就可以在完全不进行身份验证的情况下更改应用程序设置。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)
Affected Products
VendorProductAffected VersionsCPESubscribe
TECSONe-litro net unspecified ~ V6.32 -
TECSONLX-Net unspecified ~ V6.32 -
TECSONLX-Q-Net unspecified ~ V6.32 -
GOKSmartBox 4 LAN unspecified ~ V6.3 -
GOKSmartBox 4 LAN PRO unspecified ~ V6.3 -
II. Public POCs for CVE-2019-12254
#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC
III. Intelligence Information for CVE-2019-12254
Please Login to view more intelligence information
New Vulnerabilities
V. Comments for CVE-2019-12254

No comments yet


Leave a comment