[FD] netis RealTek wireless router / ADSL modem Multiple Vulnerabilities

2015-10-15 Thread Karn Ganeshen
# Exploit Title: [netis RealTek wireless router / ADSL modem Multiple Vulnerabilities] # Discovered by: Karn Ganeshen # Reported on: [October 13, 2015] # Vendor Response: [Vulnerability? What's this?] # Vendor Homepage: [www.netis-systems.com] # Version Affected: [Firmware version RTK v

[FD] PROLiNK H5004NK ADSL Wireless Modem Multiple Vulnerabilities

2015-10-15 Thread Karn Ganeshen
# Exploit Title: [PROLiNK H5004NK ADSL Wireless Modem Multiple Vulnerabilities] # Discovered by: Karn Ganeshen # Reported on: [October 13, 2015] # Vendor Response: [No process to handle vuln reports] # Vendor Homepage: [ http://www.prolink2u.com/newtemp/datacom/adsl-modem-router/381-h5004nk.html

[FD] ZTE ADSL modems - Multiple vulnerabilities

2015-11-14 Thread Karn Ganeshen
ame Password Priority admin password1 2 support password2 0 admin password3 1 + Best Regards, Karn Ganeshen -- Best Regards, Karn Ganeshen ___ Sent through the Full Disclosure mailing list https://nmap.org/mailman/listinfo/fulldisclosure Web Archives & RSS: http://seclists.org/fulldisclosure/

[FD] Cambium ePMP 1000 - Multiple Vulnerabilities

2015-11-19 Thread Karn Ganeshen
ogs etc is downloaded. HTTP/1.1 200 OK Cache-Control: no-store, no-cache, max-age=0, must-revalidate, post-check=0, pre-check=0 Cache-Control: no-cache Status: 200 OK Content-Type: application/json Content-Disposition: attachment; filename=.json Expires: 0 Date: Sun, 18 Jan 1970 16:50:21 GMT Ser

[FD] Brocade Fabric OS v6.3.1b Multiple Vulnerabilities

2015-11-30 Thread Karn Ganeshen
# Title: [Brocade Fabric OS v6.3.1b - Multiple vulnerabilities] # Discovered by: Karn Ganeshen # Vendor Homepage: [www.brocade.com] # Versions Reported: Kernel 2.6.14.2 + FabOS v6.3.1b + BootProm 1.0.9 > *version* Kernel: 2.6.14.2 Fabric OS: v6.3.1b BootProm: 1.0.9 1 *Default diagnos

[FD] LG Nortel ADSL modems - Multiple vulnerabilities

2015-12-09 Thread Karn Ganeshen
# Title: [LG Nortel ADSL modems - Multiple vulnerabilities] # Discovered by: Karn Ganeshen # Vendor Homepage: [NA] # Version Reported: [Board ID: DV2020]+Product Version: S1.064B2.3H0-0 + Software Version: 3.04L.02V.sip._LE9500.dspApp3341A2pB022f.d19e] *Timelines* April, 2015: Vulnerabilities

[FD] XZERES 442SR Wind Turbine XSS

2015-12-24 Thread Karn Ganeshen
s-id-parameter") -- Best Regards, Karn Ganeshen ___ Sent through the Full Disclosure mailing list https://nmap.org/mailman/listinfo/fulldisclosure Web Archives & RSS: http://seclists.org/fulldisclosure/

[FD] Nordex Control 2 (NC2) SCADA V16 and prior versions - XSS

2015-12-24 Thread Karn Ganeshen
/1.1 connection=basic&userName=admin%27%22%29%3B%7D%3C%2Fscript%3E%3Cscript%3Ealert%28%27xss%27%29%3C%2Fscript%3E&pw=nordex&language=en -- Best Regards, Karn Ganeshen ___ Sent through the Full Disclosure mailing list https://nmap.org/mail

[FD] eWON sa Industrial router - Multiple Vulnerabilities

2015-12-24 Thread Karn Ganeshen
issue B) but the final user is supposed to configure eWON through VPN (and thus https). Mitigating factors: This could be an issue regarding the CSRF attacks described above. However as already mentioned the eWON firmware exposure to CSRF attacks is really limited. Thus having equivalent POST and

[FD] SeaWell Networks Spectrum - Multiple Vulnerabilities

2016-01-20 Thread Karn Ganeshen
UI. It is possible to download the configs by calling the url directly *Access policy config xml* https://IP/configure_manage.php?action=download_config&file=policy.xml *Access cookie config xml* https://IP/configure_manage.php?action=download_config&file=cookie_config.xml *Access system c

[FD] GE Industrial Solutions - UPS SNMP Adapter Command Injection and Clear-text Sensitive Info Vulnerabilities

2016-02-03 Thread Karn Ganeshen
text passwords*. + I sent it out on Jan 29 but for some reason, it was not posted to FD. So sending it again. -- Best Regards, Karn Ganeshen ipositivesecurity.blogspot.in ___ Sent through the Full Disclosure mailing list https://nmap.org/mailman/l

[FD] DLink DVG­N5402SP Multiple Vulnerabilities

2016-02-03 Thread Karn Ganeshen
from the portal directly, gather clear-text admin creds, and gain full, unauthorized access to the device. -- Best Regards, Karn Ganeshen ipositivesecurity.blogspot.in ___ Sent through the Full Disclosure mailing list https://nmap.org/mailman/listinfo/fulldisclosure Web Archives & RSS: http://seclists.org/fulldisclosure/

[FD] WAGO IO PLC 758-870, 750-849, 750-849 vulnerabilities

2016-03-03 Thread Karn Ganeshen
0 ETA *226-File successfully transferred* 226 0.003 seconds (measured here), 143.76 Kbytes per second 459 bytes received in 00:00 (35.35 KiB/s) + -- Best Regards, Karn Ganeshen ___ Sent through the Full Disclosure mailing list https://nmap.org/mailman/listinfo/fulldisclosure Web Archives & RSS: http://seclists.org/fulldisclosure/

[FD] Schneider Electric Building Operation Automation Server Multiple Vulnerabilities

2016-03-03 Thread Karn Ganeshen
ill be forcefully changed, and msh has been sufficiently improved to mitigate against command injection. Issue 3, however, persists. Anyone with access to msh shell, can still drop in to root shell, and have some fun. + -- Best Regards, Karn Ganeshen __

[FD] Moxa MiiNePort - Multiple Vulnerabilities

2016-05-03 Thread Karn Ganeshen
generated per page and / or per (sensitive) function. Successful exploitation of this vulnerability allows silent execution of unauthorized actions on the device such as password change, configuration parameter changes, saving modified configuration, & device reboot. + -- Best Regards,

[FD] [ICS] Meteocontrol WEB’log Multiple Vulnerabilities

2016-05-17 Thread Karn Ganeshen
comments to ICS-CERT team to correct their report. Hopefully they will update it soon. +++++ Cheers! -- Best Regards, Karn Ganeshen ___ Sent through the Full Disclosure mailing list https://nmap.org/mailman/listinfo/fulldisclosure Web Archives & RSS: http://seclists.org/fulldisclosure/

[FD] HP StoreEver MSL6480 Tape Library v4.10 - Multiple Vulnerabilities

2016-06-16 Thread Karn Ganeshen
. Successful exploitation of this vulnerability may allow silent execution of unauthorized actions on the device such as password change, configuration parameter changes, generating system configuration archive, saving modified configuration, & device reboot. + -- Best Regards, Karn Gane

[FD] Papouch TME Temperature & Humidity Thermometers - Multiple Vulnerabilities

2016-06-16 Thread Karn Ganeshen
act due to device compromise can be severe depending upon the utility & environment where they are deployed. + -- Best Regards, Karn Ganeshen ___ Sent through the Full Disclosure mailing list https://nmap.org/mailman/listinfo/fulldisclosure Web Archiv

[FD] Sierra Wireless AirLink Raven XE Industrial 3G Gateway - Multiple Vulnerabilities

2016-06-24 Thread Karn Ganeshen
ess this issue on the Raven XE/XT. Sierra Wireless strongly recommends that the AceManager interface be disabled on the cellular WAN connection, particularly when the device is active on public networks in order to prevent exploitation of this sensitive information by internet-based attackers. +

[FD] EdgeCore - ES3526XA Manager - Multiple Vulnerabilities

2016-06-24 Thread Karn Ganeshen
*EdgeCore - Layer2+ Fast Ethernet Standalone Switch ES3526XA Manager - Multiple Vulnerabilities* Also rebranded as: *SMC TigerSwitch 10/100 SMC6128L2 Manager* Object ID: 1.3.6.1.4.1.259.8.1.5 Switch Information Main Board: Number of Ports 26 Hardware Versi

[FD] RS232-NET Converter (JTC-200) - Multiple vulnerabilities

2016-07-06 Thread Karn Ganeshen
*RS232-NET Converter (JTC-200) - Multiple vulnerabilities* About RS232-NET Converter (model JTC-200) http://www.jantek.com.tw/en/product/73 *Seen deployed in:* CHTD, Chunghwa Telecom Co., Ltd. (Taiwan) HiNet (Taiwan & China) PT Comunicacoes (Portugal) Sony Network Taiwan Limited (Taiwan) Vodafone

[FD] CIMA DocuClass ECM - Multiple Vulnerabilities

2016-07-06 Thread Karn Ganeshen
*CIMA DocuClass Enterprise Content Management - Multiple Vulnerabilities* DocuClass is a modular and scalable enterprise content management (ECM) solution that allows organizations to streamline internal operations by significantly improving the way they manage their information within a business

[FD] Multiple vulnerabilities - Powerlogic/Schneider Electric IONXXXX series Smart Meters

2016-09-08 Thread Karn Ganeshen
*Powerlogic/Schneider Electric ION series Smart Meters - Multiple security issues* *Impacted devices:* *ION7300 and potentially all ION models (based off of Powerlogic) *For example, Power Measurement Ltd. Meter ION 7330V283 ETH ETH7330V274 http://www.schneider-electric.com/download/hk/en

[FD] ELNet Energy & Electrical Power Meter - Mulitple Vulnerabilities

2016-09-08 Thread Karn Ganeshen
*ELNet **Energy & Electrical Power Meter - Mulitple Vulnerabilities* http://elnet.feniks-pro.com/Elnet-LT.php http://www.elnet.cc/product/elnet-lt/ Powermeter with color graphic display for all electrical measurements and harmonics, with TCP/IP and RS485 communication (ModBus and Bacnet), pane

[FD] BINOM3 Electric Power Quality Meter Vulnerabilities

2016-09-15 Thread Karn Ganeshen
*Universal multifunctional Electric Power Quality Meter BINOM3 - Multiple Vulnerabilities* *About* The meters are designed for autonomous operation in automated systems: • SCADA systems • Data aquisition and transmission systems • Automated data and measurement systems for revenue and technical po

[FD] Python + PostgreSQL pgAdmin4 – Insecure Library Loading Allows Code Execution

2017-02-28 Thread Karn Ganeshen
Python + PostgreSQL pgAdmin4 – Insecure Library Loading Allows Code Execution (DLL Hijacking Vulnerability) *Confirmed on* pgAdmin4 v1.1: Current version packaged with PostgreSQL v9.6.1.1 (Windows x86 Current version) *Checked on* Windows 7 SP1 + python 2.7.13 (current version) Note - This is a

[FD] LAquis SCADA Access Control Vulnerability

2017-04-07 Thread Karn Ganeshen
LCDS – Leão Consultoria e Desenvolvimento de Sistemas LTDA ME LAquis SCADA Access Control Vulnerability Vendor: LCDS – Leão Consultoria e Desenvolvimento de Sistemas LTDA ME Equipment: LAquis SCADA Vulnerability: Improper Access Control ICS-CERT Advisory https://ics-cert.us-cert.gov/advisories/IC

[FD] Sielco Sistemi Winlog SCADA Software Insecure Library Loading Allows Code Execution

2017-04-07 Thread Karn Ganeshen
Sielco Sistemi Winlog SCADA Software Insecure Library Loading Allows Code Execution Vendor: Sielco Sistemi Equipment: Winlog SCADA Software Vulnerability: Uncontrolled Search Path Element ICS-CERT Advisory https://ics-cert.us-cert.gov/advisories/ICSA-17-038-01 AFFECTED PRODUCTS The following Si

[FD] SenNet Data Logger appliances and Electricity Meters Multiple Vulnerabilities

2017-04-07 Thread Karn Ganeshen
SenNet Data Logger appliances and Electricity Meters Multiple Vulnerabilities Note: Vendor has released the fix. Details to be documented in ICS-CERT Advisory. About SenNet is a trademark of Satel Spain that offers monitoring and remote-control solutions for businesses. Our engineers develop, int

[FD] Cambium SNMP Security Vulnerabilities

2017-04-07 Thread Karn Ganeshen
Cambium SNMP Security Vulnerabilities AFFECTED PRODUCTS Cambium ePMP 1000 Cambium ePMP 2000 Cambium PMP XXX Cambium ForceXXX models Potentially all other models IMPACT These vulnerabilities may allow an attacker to access device configuration as well as make unauthorized changes to the device c

[FD] Carlo Gavazzi VMUC-EM - Multiple Vulnerabilities

2017-04-07 Thread Karn Ganeshen
*VMU-C Web-Server solution for photovoltaic applications* VMU-C EM is a data logger system for small to medium projects, VMUC-Y EM is a hardware data aggregator for medium to larger projects and Em2 Server is a software solution for large projects. They are designed to complement the extensive lin

[FD] Microsoft Office Patch Installer Executables - Insecure Library Loading Allows Code Execution

2017-06-29 Thread Karn Ganeshen
Microsoft Office Patch Installer Executables - Insecure Library Loading Allows Code Execution Vulnerability: DLL Hijacking / DLL Side Loading Advisory URL: https://ipositivesecurity.com/2017/06/15/microsoft-office-patch-installers-insecure-library-loading-allow-code-execution/ ---

[FD] Microsoft Machine Debug Manager (mdm) DLL side loading vulnerability

2017-06-29 Thread Karn Ganeshen
Microsoft Machine Debug Manager (mdm) DLL side loading vulnerability Vulnerability: DLL Hijacking / DLL Side Loading Advisory URL: https://ipositivesecurity.com/2017/06/15/microsoft-machine-debug-manager-mdm-insecure-library-loading-allows-code-execution/ ABOUT --

[FD] Digital Canal Structural Wind Analysis Stack Buffer Overflow

2017-06-29 Thread Karn Ganeshen
Vendor: Digital Canal Structural Equipment: Wind Analysis Vulnerability: Stack-Based Buffer Overflow Advisory URL: https://ipositivesecurity.com/2017/06/15/ics-digital-canal-structural-wind-analysis-stack-buffer-overflow/ ICS-CERT Advisory https://ics-cert.us-cert.gov/advisories/ICSA-17-157-02 --

[FD] Trihedral VTScada Multiple Vulnerabilities

2017-06-29 Thread Karn Ganeshen
Vendor: Trihedral Equipment: VTScada Vulnerability: Resource Consumption, Cross-Site Scripting, Information Exposure Advisory URL: https://ipositivesecurity.com/2017/06/15/ics-trihedral-vtscada-multiple-vulnerabilities/ ICS-CERT Advisory https://ics-cert.us-cert.gov/advisories/ICSA-17-164-01

[FD] Schneider Electric Wonderware InduSoft Web Studio Privilege Escalation

2017-06-29 Thread Karn Ganeshen
Vendor: Schneider Electric Equipment: Wonderware InduSoft Web Studio Vulnerability: Incorrect Default Permissions Advisory URL: https://ipositivesecurity.com/2017/05/19/ics-schneider-electric-wonderware-indusoft-web-studio-privilege-escalation/ ICS-CERT Advisory https://ics-cert.us-cert.gov/adviso

[FD] BLF-Tech LLC VisualView HMI Software – Insecure Library Loading Allows Code Execution

2017-06-29 Thread Karn Ganeshen
Vendor: BLF-Tech LLC Equipment: VisualView HMI Software Vulnerability: DLL Hijacking Advisory URL: https://ipositivesecurity.com/2017/05/18/ics-blf-tech-llc-visualview-hmi-software-insecure-library-loading-allows-code-execution/ ICS-CERT Advisory https://ics-cert.us-cert.gov/advisories/ICSA-17-115

[FD] Schneider Electric Interactive Graphical SCADA System Software – Insecure Library Loading Allows Code Execution

2017-06-29 Thread Karn Ganeshen
Vendor: Schneider Electric Equipment: Interactive Graphical SCADA System (IGSS) Software Vulnerability: DLL Hijacking Advisory URL: https://ipositivesecurity.com/2017/05/18/ics-schneider-electric-interactive-graphical-scada-system-software-insecure-library-loading-allows-code-execution/ ICS-CERT A

[FD] Schneider Electric Pro-Face WinGP – Runtime.exe – Insecure Library Loading Allows Code Execution

2017-06-30 Thread Karn Ganeshen
[ICS] Schneider Electric Pro-Face WinGP – Runtime.exe – Insecure Library Loading Allows Code Execution Vendor: Schneider Electric Equipment: Pro-Face WinGP Vulnerability: Uncontrolled Search Path Element (DLL side-loading) Advisory URL: https://ipositivesecurity.com/2017/06/28/ics-schneider-elect

[FD] [ICS] Schneider Electric Pro-Face WinGP – Insecure Library Loading Allows Code Execution

2017-08-31 Thread Karn Ganeshen
reproduce 1. Generate a dll payload msfvenom –p windows/exec cmd=calc.exe –f dll –o i2capi.dll 2. Place this dll in any directory defined in the PATH environment variable C:\Pro-face\WinGP\ 3. Run Runtime.exe -> calc.exe ​ executes + Best Regards, Karn Ganes

[FD] [ICS] Solar Controls WATTConfig M Software – Insecure Library Loading Allows Code Execution

2017-08-31 Thread Karn Ganeshen
WattConfigM.exe -> calc.exe executes + Best Regards, Karn Ganeshen ___ Sent through the Full Disclosure mailing list https://nmap.org/mailman/listinfo/fulldisclosure Web Archives & RSS: http://seclists.org/fulldisclosure/

[FD] [ICS] Solar Controls Heating Control Downloader – Insecure Library Loading Allows Code Execution

2017-08-31 Thread Karn Ganeshen
HCDownloader.exe -> calc.exe executes + Best Regards, Karn Ganeshen ___ Sent through the Full Disclosure mailing list https://nmap.org/mailman/listinfo/fulldisclosure Web Archives & RSS: http://seclists.org/fulldisclosure/

[FD] [ICS] SIMPlight SCADA software – Insecure Library Loading Allows Code Execution

2017-08-31 Thread Karn Ganeshen
this dll in any directory defined in the PATH environment variable C:\app-folder-RW\ 3. Run ArchBrowser.exe (or any from listed above) -> calc.exe will execute + Best Regards, Karn Ganeshen ___ Sent through the Full Disclosure mailing list ht

[FD] [ICS] SpiderControl SCADA Web Server – Directory Traversal Vulnerability

2017-08-31 Thread Karn Ganeshen
A:N). + Best Regards, Karn Ganeshen ___ Sent through the Full Disclosure mailing list https://nmap.org/mailman/listinfo/fulldisclosure Web Archives & RSS: http://seclists.org/fulldisclosure/

[FD] [ICS] SpiderControl SCADA MicroBrowser – Stack Buffer Overflow Vulnerability

2017-08-31 Thread Karn Ganeshen
base score of 7.3 has been assigned; the CVSS vector string is (AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L). + Best Regards, Karn Ganeshen ___ Sent through the Full Disclosure mailing list https://nmap.org/mailman/listinfo/fulldisclosure Web Archives &

[FD] [ICS] Schneider Electric Trio TView – vulnerable JRE versions in use

2017-08-31 Thread Karn Ganeshen
CVSS base score of 4.0-6.9, and * 24 vulnerabilities were identified as having a CVSS base score of 0.0-3.9. + Best Regards, Karn Ganeshen ___ Sent through the Full Disclosure mailing list https://nmap.org/mailman/listinfo/fulldisclosure Web Archives

[FD] [ICS] Moxa SoftNVR-IA Live Viewer – Insecure Library Loading Allows Code Execution

2017-08-31 Thread Karn Ganeshen
when the application starts, while few are loaded when the application is exited. Thus, code execution can happen at the start or at exit time of the application run. + Best Regards, Karn Ganeshen ___ Sent through the Full Disclosure mailing list https

[FD] [ICS] AzeoTech DAQFactory – Insecure Default Permissions and Insecure Library Loading Allows Code Execution

2017-08-31 Thread Karn Ganeshen
a dll payload msfvenom –p windows/exec cmd=calc.exe –f dll –o pegrc32a.dll 2. Place this dll in install directory (or any directory defined in the PATH environment variable) C:\DAQFactory\ 3. Run DAQFactory.exe ​ -> calc.exe executes​ + Best Regards, Karn Ganes

[FD] JanTek JTC-200 Vulnerabilities

2017-10-31 Thread Karn Ganeshen
). Technical Details https://ipositivesecurity.com/2016/07/05/rs232-net-converter-model-jtc-200-multiple-vulnerabilities/ + Best Regards, Karn Ganeshen ___ Sent through the Full Disclosure mailing list https

[FD] [ICS] SpiderControl SCADA Web Server Improper Privilege Management Vulnerability

2017-10-31 Thread Karn Ganeshen
Regards, Karn Ganeshen ___ Sent through the Full Disclosure mailing list https://nmap.org/mailman/listinfo/fulldisclosure Web Archives & RSS: http://seclists.org/fulldisclosure/

[FD] [ICS] Progea Movicon SCADA/HMI Vulnerabilities

2017-10-31 Thread Karn Ganeshen
/S:U/C:H/I:H/A:H). + Best Regards, Karn Ganeshen ___ Sent through the Full Disclosure mailing list https://nmap.org/mailman/listinfo/fulldisclosure Web Archives & RSS: http://seclists.org/fulldisclosure/