CVE-2020-29127
Fujitsu Eternus Storage DX200 S4 Broken Authentication
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
An issue was discovered on Fujitsu Eternus Storage DX200 S4 devices through 2020-11-25. After logging into the portal as a root user (using any web browser), the portal can be accessed with root privileges when the URI cgi-bin/csp?cspid={XXXXXXXXXX}&csppage=cgi_PgOverview&csplang=en is visited from a different web browser.
Se detectó un problema en los dispositivos Fujitsu Eternus Storage DX200 S4 hasta el 25-11-2020. Después de iniciar sesión en el portal como usuario root (usando cualquier navegador web), el portal puede ser accedido con privilegios root cuando es visitado el URI cgi-bin/csp?cspid={XXXXXXXXXX}&csppage=cgi_PgOverview&csplang=en desde un navegador web diferente
Fujitsu Eternus Storage DX200 S4 fails to set cookies for authentication allowing for replay of URLs to achieve root level privileges.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-11-26 CVE Reserved
- 2020-11-26 CVE Published
- 2024-08-04 CVE Updated
- 2024-08-04 First Exploit
- 2024-08-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-287: Improper Authentication
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
https://seccops.com/fujitsu-eternus-storage-dx200-s4-broken-authentication | Third Party Advisory | |
https://www.first.org/members/teams/fujitsu_psirt | Third Party Advisory |
URL | Date | SRC |
---|---|---|
http://packetstormsecurity.com/files/160255/Fujitsu-Eternus-Storage-DX200-S4-Broken-Authentication.html | 2024-08-04 | |
https://cxsecurity.com/issue/WLB-2020110215 | 2024-08-04 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Fujitsu Search vendor "Fujitsu" | Eternus Storage Dx200 S4 Firmware Search vendor "Fujitsu" for product "Eternus Storage Dx200 S4 Firmware" | <= 2020-11-25 Search vendor "Fujitsu" for product "Eternus Storage Dx200 S4 Firmware" and version " <= 2020-11-25" | - |
Affected
| in | Fujitsu Search vendor "Fujitsu" | Eternus Storage Dx200 S4 Search vendor "Fujitsu" for product "Eternus Storage Dx200 S4" | - | - |
Safe
|