1 results (0.007 seconds)

CVSS: 10.0EPSS: 44%CPEs: 2EXPL: 2

An issue was discovered on Fujitsu Eternus Storage DX200 S4 devices through 2020-11-25. After logging into the portal as a root user (using any web browser), the portal can be accessed with root privileges when the URI cgi-bin/csp?cspid={XXXXXXXXXX}&csppage=cgi_PgOverview&csplang=en is visited from a different web browser. Se detectó un problema en los dispositivos Fujitsu Eternus Storage DX200 S4 hasta el 25-11-2020. Después de iniciar sesión en el portal como usuario root (usando cualquier navegador web), el portal puede ser accedido con privilegios root cuando es visitado el URI cgi-bin/csp? • http://packetstormsecurity.com/files/160255/Fujitsu-Eternus-Storage-DX200-S4-Broken-Authentication.html https://cxsecurity.com/issue/WLB-2020110215 https://seccops.com/fujitsu-eternus-storage-dx200-s4-broken-authentication https://www.first.org/members/teams/fujitsu_psirt • CWE-287: Improper Authentication •