Vulnerability CVE-2020-29127


Published: 2020-11-30

Description:
An issue was discovered on Fujitsu Eternus Storage DX200 S4 devices through 2020-11-25. After logging into the portal as a root user (using any web browser), the portal can be accessed with root privileges when the URI cgi-bin/csp?cspid={XXXXXXXXXX}&csppage=cgi_PgOverview&csplang=en is visited from a different web browser.

See advisories in our WLB2 database:
Topic
Author
Date
Med.
Fujitsu Eternus Storage DX200 S4 Broken Authentication
Seccops
26.11.2020

Type:

CWE-287

(Improper Authentication)

CVSS2 => (AV:N/AC:L/Au:N/C:C/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
10/10
10/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Complete

 References:
http://packetstormsecurity.com/files/160255/Fujitsu-Eternus-Storage-DX200-S4-Broken-Authentication.html
https://cxsecurity.com/issue/WLB-2020110215
https://seccops.com/fujitsu-eternus-storage-dx200-s4-broken-authentication/
https://www.first.org/members/teams/fujitsu_psirt

Copyright 2021, cxsecurity.com

 

Back to Top