ISE SOHO Vulnerability Catalog Published - Independent Security ...
ISE SOHO Vulnerability Catalog Published - Independent Security ...
ISE SOHO Vulnerability Catalog Published - Independent Security ...
You also want an ePaper? Increase the reach of your titles
YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.
Impact<br />
If an unauthenticated attacker is able to access the Belkin routers web management<br />
interface or perform a CSRF attack, the attacker can bypass the routers authentication<br />
verification and gain full control of the router.<br />
Recommendations to the Vendor<br />
♦ Validate HTTP Authorization Header<br />
♦ Additional information for vendors regarding immediate and long term fixes for<br />
these issues can be found here: http://www.securityevaluators.com/content/casestudies/routers/#recommendationsVendors<br />
Solution<br />
♦ There currently is not a solution to this problem.<br />
♦ Restrict access to WAN services such as remote management to prevent an<br />
attacker from gaining access if an attack is successful.<br />
Disclosure Timeline<br />
♦ 2/11/2013 - Notified Belkin<br />
♦ 4/15/2013 - Public Disclosure<br />
*In between the initial notification and the public disclosure, <strong>ISE</strong> reached out to Belkin multiple times<br />
requesting that our vulnerabilities were escalated to the proper support team.<br />
References<br />
♦ Advisory/Video: http://infosec42.blogspot.com<br />
♦ http://securityevaluators.com/content/case-studies/<br />
Credit<br />
♦ Discovered By: Jacob Holcomb – <strong>Security</strong> Analyst @ <strong>Independent</strong> <strong>Security</strong><br />
Evaluators<br />
♦ Exploited By: Jacob Holcomb – <strong>Security</strong> Analyst @ <strong>Independent</strong> <strong>Security</strong><br />
Evaluators<br />
<br />
73