ID

VAR-E-201812-0198


CVE

cve_id:CVE-2018-19616

Trust: 1.5

sources: PACKETSTORM: 150619 // EXPLOIT-DB: 45937

EDB ID

45937


TITLE

Rockwell Automation Allen-Bradley PowerMonitor 1000 - Incorrect Access Control Authentication Bypass - Hardware webapps Exploit

Trust: 0.6

sources: EXPLOIT-DB: 45937

DESCRIPTION

Rockwell Automation Allen-Bradley PowerMonitor 1000 - Incorrect Access Control Authentication Bypass. CVE-2018-19616 . webapps exploit for Hardware platform

Trust: 0.6

sources: EXPLOIT-DB: 45937

AFFECTED PRODUCTS

vendor:rockwellmodel:automation allen-bradley powermonitorscope:eqversion:1000

Trust: 1.6

vendor:rockwellmodel:automation allen-bradley powermonitor authenticationscope:eqversion:1000

Trust: 0.5

sources: PACKETSTORM: 150619 // EXPLOIT-DB: 45937 // EDBNET: 100417

EXPLOIT

# Exploit Title: Rockwell Automation Allen-Bradley PowerMonitor 1000 - Incorrect Access Control
# Date: 2018-11-27
# Exploit Author: Luca.Chiou
# Vendor Homepage: https://www.rockwellautomation.com/
# Version: 1408-EM3A-ENT B
# Tested on: It is a proprietary devices: https://ab.rockwellautomation.com/zh/Energy-Monitoring/1408-PowerMonitor-1000
# CVE : CVE-2018-19616

# 1. Description:
# In Rockwell Automation Allen-Bradley PowerMonitor 1000 web page, there are a few buttons are disabled,
# such as “Edit”, “Remove”, “AddNew”, “Change Policy Holder” and “Security Configuration”.
# View the source code of login page, those buttons/functions just use the “disabled” parameter to control the access right.
# It is allow attackers using proxy to erase the “disabled” parameter, and enable those buttons/functions.
# Once those buttons/functions are enabled.
# Attackers is capable to add a new user who have administrator right.

Trust: 1.0

sources: EXPLOIT-DB: 45937

EXPLOIT LANGUAGE

txt

Trust: 0.6

sources: EXPLOIT-DB: 45937

PRICE

free

Trust: 0.6

sources: EXPLOIT-DB: 45937

TYPE

Incorrect Access Control Authentication Bypass

Trust: 1.6

sources: EXPLOIT-DB: 45937 // EDBNET: 100417

TAGS

tag:Authentication Bypass / Credentials Bypass (AB/CB)

Trust: 1.0

tag:exploit

Trust: 0.5

tag:bypass

Trust: 0.5

sources: PACKETSTORM: 150619 // EXPLOIT-DB: 45937

CREDITS

Luca.Chiou

Trust: 0.6

sources: EXPLOIT-DB: 45937

EXTERNAL IDS

db:EXPLOIT-DBid:45937

Trust: 1.6

db:NVDid:CVE-2018-19616

Trust: 1.5

db:EDBNETid:100417

Trust: 0.6

db:PACKETSTORMid:150619

Trust: 0.5

sources: PACKETSTORM: 150619 // EXPLOIT-DB: 45937 // EDBNET: 100417

REFERENCES

url:https://nvd.nist.gov/vuln/detail/cve-2018-19616

Trust: 1.5

url:https://www.exploit-db.com/exploits/45937/

Trust: 0.6

sources: PACKETSTORM: 150619 // EXPLOIT-DB: 45937 // EDBNET: 100417

SOURCES

db:PACKETSTORMid:150619
db:EXPLOIT-DBid:45937
db:EDBNETid:100417

LAST UPDATE DATE

2022-07-27T09:14:59.593000+00:00


SOURCES RELEASE DATE

db:PACKETSTORMid:150619date:2018-12-05T04:44:44
db:EXPLOIT-DBid:45937date:2018-12-04T00:00:00
db:EDBNETid:100417date:2018-12-08T00:00:00