目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2020-29667 PoC — Lan ATMService M3 ATM 代码问题漏洞

来源
关联漏洞
标题: Lan ATMService M3 ATM 代码问题漏洞 (CVE-2020-29667)
Description:Lan ATMService M3 ATM Monitoring System是俄罗斯Lan ATMService公司的一款可用于对ATM机器进行监控的软件。 Lan ATMService M3 ATM 6.1.0存在安全漏洞,攻击者可利用该漏洞可以使用默认的cookie值,来实现对系统会话过期不足的控制。
介绍
# CVE-2020-29667
Insufficient Session Expiration | Predefined Cookie Value

[Suggested description]
In Lan ATMService M3 ATM Monitoring System 6.1.0, a remote attacker able to use a default cookie value, such as PHPSESSID=LANIT-IMANAGER, can achieve control over the system and operate remote ATM maschines current state, because of Insufficient Session Expiration and Predefined Cookie Value.
------------------------------------------
[Additional Information]
A letter was sent to the vendor about the vulnerability.
------------------------------------------
[VulnerabilityType Other]
CWE-613: Insufficient Session Expiration
------------------------------------------
[Vendor of Product]
Lan ATMService LLC (http://lanatmservice.ru/)
------------------------------------------
[Affected Product Code Base]
Affected version: M3 ATM Monitoring System 6.1.0. There are no fixed versions and any response from developers.
------------------------------------------
[Affected Component]
Application misconfiguration, that allows to remote attacker use a hardcoded predefined cookie value.
------------------------------------------
[Attack Type]
Remote
------------------------------------------
[Impact Information Disclosure]
true
------------------------------------------
[Impact Loss of Integrity]
Low
------------------------------------------
[Impact Loss of Availability]
High
------------------------------------------
[Attack Vectors]
A remote attacker can use a predefined cookie value for control over the system for operate ATM machines current state.
------------------------------------------
[Discoverer]
Dmitry Kuramin (Jet Infosystems, jet.su)
------------------------------------------
[Reference]
https://jet.su
文件快照

登录后查看神龙缓存的 POC 文件快照

登录查看
备注
    1. 建议优先通过来源进行访问。
    2. 本地 POC 快照面向订阅用户开放;当原始来源失效或无法访问时,本地镜像作为订阅权益的一部分提供。
    3. 持续抓取、验证、维护这份 POC 档案需要不少投入,因此本地快照已纳入付费订阅。您的订阅是让这份资料能继续走下去的关键,由衷感谢。 查看订阅方案 →