CVE-2019-12254
In multiple Tecson Tankspion and GOKs SmartBox 4 products the affected application doesn't properly restrict access to an endpoint that is responsible for saving settings, to a unauthenticated user with limited access rights. Based on the lack of adequately implemented access-control rules, by accessing a specific uniform resource locator (URL) on the web server, a malicious user is able to change the application settings without authenticating at all, which violates originally laid ACL rules.
Published:May 6, 2022
Last Modified:Nov 21, 2024
EPS:May 6, 2022
EPSS Score:0.00812
CVSS Score:9.8
Affected Products
Vendor
Product
Action
Vendor
Gok
Product
Smartbox 4 Lan
Gok
Smartbox 4 Lan
Vendor
Gok
Product
Smartbox 4 Lan Firmware
Gok
Smartbox 4 Lan Firmware
Vendor
Gok
Product
Smartbox 4 Lan Pro
Gok
Smartbox 4 Lan Pro
Vendor
Gok
Product
Smartbox 4 Lan Pro Firmware
Gok
Smartbox 4 Lan Pro Firmware
Vendor
Tecson
Product
E-litro Net
Tecson
E-litro Net
Vendor
Tecson
Product
E-litro Net Firmware
Tecson
E-litro Net Firmware
Vendor
Tecson
Product
Lx-net
Tecson
Lx-net
Vendor
Tecson
Product
Lx-net Firmware
Tecson
Lx-net Firmware
Vendor
Tecson
Product
Lx-q-net
Tecson
Lx-q-net
Vendor
Tecson
Product
Lx-q-net Firmware
Tecson
Lx-q-net Firmware
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
