CVE-2019-12254
Severity CVSS v4.0:
Pending analysis
Type:
CWE-287
Authentication Issues
Publication date:
06/05/2022
Last modified:
16/05/2022
Description
In multiple Tecson Tankspion and GOKs SmartBox 4 products the affected application doesn't properly restrict access to an endpoint that is responsible for saving settings, to a unauthenticated user with limited access rights. Based on the lack of adequately implemented access-control rules, by accessing a specific uniform resource locator (URL) on the web server, a malicious user is able to change the application settings without authenticating at all, which violates originally laid ACL rules.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Base Score 2.0
10.00
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:gok:smartbox_4_lan_firmware:*:*:*:*:*:*:*:* | ||
| cpe:2.3:h:gok:smartbox_4_lan:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:gok:smartbox_4_lan_pro_firmware:*:*:*:*:*:*:*:* | ||
| cpe:2.3:h:gok:smartbox_4_lan_pro:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:tecson:lx-q-net_firmware:*:*:*:*:*:*:*:* | ||
| cpe:2.3:h:tecson:lx-q-net:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:tecson:lx-net_firmware:*:*:*:*:*:*:*:* | ||
| cpe:2.3:h:tecson:lx-net:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:tecson:e-litro_net_firmware:*:*:*:*:*:*:*:* | ||
| cpe:2.3:h:tecson:e-litro_net:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



