ID

VAR-202002-0803


CVE

CVE-2013-7286


TITLE

MobileIron VSP and Sentry Vulnerability regarding inadequate protection of credentials in

Trust: 0.8

sources: JVNDB: JVNDB-2013-007270

DESCRIPTION

MobileIron VSP < 5.9.1 and Sentry < 5.0 has a weak password obfuscation algorithm. MobileIron VSP and Sentry Exists in an inadequate protection of credentials.Information may be obtained. The MobileIron Virtual Smartphone Platform (VSP) and Sentry are products of MobileIron. VSP is a virtual smartphone platform. Sentry is a smart gateway product. An attacker could exploit the vulnerability to view encrypted data for sensitive information. MobileIron VSP and Sentry are prone to a security weakness that may allow attackers to obtain sensitive information. This may lead to other attacks. MobileIron VSP prior to 5.9.1 and Sentry 5.0 are vulnerable. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Matta Consulting - Matta Advisory https://www.trustmatta.com MobileIron Multiple Products Authentication Bypass Vulnerability Advisory ID: MATTA-2013-004 CVE reference: CVE-2014-1409, CVE-2013-7286 Affected platforms: VSP and Sentry Version: VSP < 5.9.1 and Sentry < 5.0 Date: 2013-December-19 Security risk: Critical Researcher: Nico Leidecker Vendor Status: Patch released Vulnerability Disclosure Policy: https://www.trustmatta.com/advisories/matta-disclosure-policy-01.txt Permanent URL: https://www.trustmatta.com/advisories/MATTA-2013-004.txt ===================================================================== Description: During an external penetration test exercise for one of our clients, an authentication bypass vulnerability was found in the administrative interface of a MobileIron deployment. This ultimately allowed us to, gain access to our client's internal network. The 'j_username' parameter of the script at https://<target>/mics/j_spring_security_check is vulnerable to blind XPath Injection, allowing an unauthenticated attacker to retrieve the underlying XML document. This XML document is an excerpt of the configuration file of the device. It contains obfuscated passwords and, depending on configuration, might contain domain credentials and allow the attacker to reposition both internally and on any of the attached devices. This vulnerability has been assigned CVE-2014-1409. AES-ECB-PKCS1.5 with a known, shared key. While we won't release a full-featured exploit for the vulnerability, we will release a PoC to confirm whether the hashes are indeed vulnerable. The vendor has confirmed that a stronger encryption method is used since release 5.7. This vulnerability has been assigned CVE-2013-7286. [1] https://www.hackinparis.com/sites/hackinparis.com/files/MDM-HIP_2013.pdf NB: A second insecure encryption scheme is described in [1], MITRE has assigned CVE-2013-7287 to that separate vulnerability. ===================================================================== Base64 encoded script to confirm whether the hash provided is vulnerable to CVE-2013-7286: IyEvdXNyL2Jpbi9lbnYgcHl0aG9uCiMKIyAgTW9iaWxlSXJvbiB1c2VzIEFFUy1FQ0ItUEtDUzEu NSAod2l0aCBhIGtub3duIGtleSkKIyB0byBzdG9yZSBjcmVkZW50aWFscy4uLiBXaGF0IGEgYnJp bGxpYW50IGlkZWEhCiMKIyBUaGlzIHNjcmlwdCBpcyBhYm91dCBjaGVja2luZyB3aGV0aGVyIHRo ZSBwcm92aWRlZAojIGhhc2ggaXMgdnVsbmVyYWJsZSB0byBDVkUtMjAxMy03Mjg2IG9yIG5vdC4K IwojIE5leHRHZW4kIH4gMjAxMwoKaW1wb3J0IHN5cwppbXBvcnQgYmluYXNjaWkKaW1wb3J0IGhh c2hsaWIKaW1wb3J0IHN0cmluZwpmcm9tIENyeXB0by5DaXBoZXIgaW1wb3J0IEFFUwoKaWYgbGVu KHN5cy5hcmd2KTwyOiAgICAKIHN5cy5leGl0KCdVc2FnZTogLi9DVkUtMjAxMy03Mjg2LnB5IDxi YXNlNjRlbmNvZGVkIGJsb2I +JykKCkJTID0gOAp1bnBhZCA9IGxhbWJkYSBzIDogc1swOi1vcmQo c1stMV0pXQoKaWYgX19uYW1lX189PSAiX19tYWluX18iOgogICAgIyBHZW5lcmF0ZSB0aGUgbWFz dGVyIGtleS4uLgogICAgIyBZZXMuIEl0J3Mgbm90IGEgdHlwbyEKICAgIHBocmFzZSA9ICdIYWt1 bmEgbWF0YXRhIHdoYXQgYSB3b2RlcmZ1bCBwaHJhc2UnCiAgICBtID0gaGFzaGxpYi5zaGExKCkK ICAgIG0udXBkYXRlKHBocmFzZSkKIyBXZSBvbmx5IHdhbnQgdGhlIDE2IGZpcnN0IGJ5dGVzICgx MjhiaXQga2V5LCAxNjBiaXQgaGFzaCBmdW5jdGlvbikKICAgIGtleSA9IG0uZGlnZXN0KClbOjE2 XQogICAgY2lwaGVydGV4dCA9IGJpbmFzY2lpLmEyYl9iYXNlNjQoc3lzLmFyZ3ZbMV0pCiAgICBj aXBoZXIgPSBBRVMubmV3KGtleSwgQUVTLk1PREVfRUNCKSAKICAgIHBsYWludGV4dCA9IHVucGFk KGNpcGhlci5kZWNyeXB0KGNpcGhlcnRleHQpKQogICAgdnVsbmVyYWJsZSA9IGxlbihwbGFpbnRl eHQpID4gMCBhbmQgYWxsKGMgaW4gc3RyaW5nLnByaW50YWJsZSBmb3IgYyBpbiBwbGFpbnRleHQp CiAgICBwcmludCAnJXNWVUxORVJBQkxFIFRPIENWRS0yMDEzLTcyODYnICUgKCcnIGlmIHZ1bG5l cmFibGUgZWxzZSAnTk9UICcpCg== ===================================================================== Impact Successful exploitation allows an unauthenticated attacker to take over the device and potentially any device attached to it as well as the Active Directory Domain it might be linked to. ===================================================================== Versions affected: - - Sentry Standalone < 5 - - VSP < 5.9.1 ===================================================================== Workaround: Restrict access to the MICS service (administrative interface) to specific hosts: MICS Portal -> Security -> Portal ACLs -> System Manager Portal ACL ===================================================================== Credits This vulnerability was discovered by Nico Leidecker from Matta Consulting. ===================================================================== History 19-12-13 initial discovery 30-12-13 client has mitigated the vulnerability 30-12-13 initial attempt to contact the vendor 30-12-13 reply from the vendor 31-12-13 a draft of this advisory is sent to the vendor 03-01-14 vendor can't reproduce / ask for more details 03-01-14 more details are sent 07-01-14 vendor recognize that there is a bug but dissmisses it as a security vulnerability 07-01-14 more details are sent 14-01-14 a week lapsed, no reply... we chase it up 14-01-14 vendor reply: they're working on a response 15-01-14 vendor respond: reclassify the bug as a security issue, indicate that they indend on fixing the bug in the Q1 release, provide a workaround and ask for us to hold on releasing the advisory until the release is published 15-01-14 we agree to a deadline extension, send the CVEs MITRE has assigned ... 19-02-14 vendor release 5.9.1 (but doesn't let us know) ... 31-03-14 vendor indicate that the release of VSP 6 is delayed but the bugs have been fixed in 5.9.1 02-04-14 release of this advisory ===================================================================== About Matta Matta is a privately held company with Headquarters in London, and a European office in Amsterdam. Established in 2001, Matta operates in Europe, Asia, the Middle East and North America using a respected team of senior consultants. Matta is an accredited provider of Tiger Scheme training and conducts regular research. https://www.trustmatta.com https://www.trustmatta.com/training.html https://www.trustmatta.com/network-penetration-testing.html https://www.trustmatta.com/vulnerability-assessment.html ===================================================================== Disclaimer and Copyright Copyright (c) 2014 Matta Consulting Limited. All rights reserved. This advisory may be distributed as long as its distribution is free-of-charge and proper credit is given. The information provided in this advisory is provided "as is" without warranty of any kind. Matta Consulting disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Matta Consulting or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Matta Consulting or its suppliers have been advised of the possibility of such damages. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQEcBAEBCAAGBQJTO/cTAAoJELJDQjn66kB28ysIAILzCnK9mifpyjswSKOJPzUi EgcexJdVIjWZf32gLi202YCHJkiIXNGfG390HrWMQZZWU2l+lEb4cMb4NH8xsjzg 06GbBnrRzBcE35dhO3C0aHuPFh7MRQzbRM4mVyPg1ViUlM7Lb9kQBoD6xdS4gZ09 SaNAdm44WrvGiFAO8yuT56cjHZ1ZYfr+iHQjxY7UIrvmzKKSvMnvv13Fy2CIrRPe zk7QLfyxszbR/eo+HOroNhHAPnfl8Mu0Y/1ihFTJF96irCPuejR7v9WzqlJxRfZB ZQJCKnz1c9cCDPxNY9GliBKT0FlkLX+IOVP/TF40jT7Zk6f+cWgOXcghlgnyunA= =XxBr -----END PGP SIGNATURE-----

Trust: 2.61

sources: NVD: CVE-2013-7286 // JVNDB: JVNDB-2013-007270 // CNVD: CNVD-2014-03884 // BID: 66633 // VULMON: CVE-2013-7286 // PACKETSTORM: 125990

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2014-03884

AFFECTED PRODUCTS

vendor:attmodel:mobileiron sentryscope:ltversion:5.0

Trust: 1.0

vendor:attmodel:mobileiron virtual smartphone platformscope:ltversion:5.9.1

Trust: 1.0

vendor:apachemodel:sentryscope:eqversion:5.0

Trust: 0.8

vendor:mobileironmodel:virtual smartphone platformscope:eqversion:5.9.1

Trust: 0.8

vendor:mobileironmodel:virtual smartphone platformscope:ltversion:5.9.1

Trust: 0.6

vendor:mobileironmodel:sentryscope:ltversion:5.0

Trust: 0.6

vendor:mobileironmodel:virtual smartphone platformscope:eqversion:5.9

Trust: 0.3

vendor:mobileironmodel:sentryscope:eqversion:4.9

Trust: 0.3

vendor:mobileironmodel:virtual smartphone platformscope:neversion:5.9.1

Trust: 0.3

vendor:mobileironmodel:sentryscope:neversion:5.0

Trust: 0.3

sources: CNVD: CNVD-2014-03884 // BID: 66633 // JVNDB: JVNDB-2013-007270 // NVD: CVE-2013-7286

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2013-7286
value: HIGH

Trust: 1.0

NVD: JVNDB-2013-007270
value: HIGH

Trust: 0.8

CNVD: CNVD-2014-03884
value: LOW

Trust: 0.6

CNNVD: CNNVD-201406-533
value: HIGH

Trust: 0.6

VULMON: CVE-2013-7286
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2013-7286
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.1

NVD: JVNDB-2013-007270
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.8

CNVD: CNVD-2014-03884
severity: LOW
baseScore: 2.1
vectorString: AV:L/AC:L/AU:N/C:N/I:N/A:P
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 3.9
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

nvd@nist.gov: CVE-2013-7286
baseSeverity: HIGH
baseScore: 7.5
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 3.6
version: 3.1

Trust: 1.0

NVD: JVNDB-2013-007270
baseSeverity: HIGH
baseScore: 7.5
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: CNVD: CNVD-2014-03884 // VULMON: CVE-2013-7286 // JVNDB: JVNDB-2013-007270 // CNNVD: CNNVD-201406-533 // NVD: CVE-2013-7286

PROBLEMTYPE DATA

problemtype:CWE-326

Trust: 1.0

problemtype:CWE-522

Trust: 0.8

sources: JVNDB: JVNDB-2013-007270 // NVD: CVE-2013-7286

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201406-533

TYPE

encryption problem

Trust: 0.6

sources: CNNVD: CNNVD-201406-533

CONFIGURATIONS

sources: JVNDB: JVNDB-2013-007270

PATCH

title:Apache Sentryurl:https://sentry.apache.org/

Trust: 0.8

title:Top Pageurl:https://www.mobileiron.com/

Trust: 0.8

title:Patch for MobileIron VSP and Sentry Information Disclosure Vulnerabilityurl:https://www.cnvd.org.cn/patchInfo/show/46761

Trust: 0.6

title:MobileIron VSP and Sentry Weak Crypto Security Vulnerability Fixesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=108053

Trust: 0.6

sources: CNVD: CNVD-2014-03884 // JVNDB: JVNDB-2013-007270 // CNNVD: CNNVD-201406-533

EXTERNAL IDS

db:NVDid:CVE-2013-7286

Trust: 3.5

db:BIDid:66633

Trust: 0.9

db:JVNDBid:JVNDB-2013-007270

Trust: 0.8

db:CNVDid:CNVD-2014-03884

Trust: 0.6

db:CNNVDid:CNNVD-201406-533

Trust: 0.6

db:PACKETSTORMid:125990

Trust: 0.2

db:VULMONid:CVE-2013-7286

Trust: 0.1

sources: CNVD: CNVD-2014-03884 // VULMON: CVE-2013-7286 // BID: 66633 // JVNDB: JVNDB-2013-007270 // PACKETSTORM: 125990 // CNNVD: CNNVD-201406-533 // NVD: CVE-2013-7286

REFERENCES

url:http://seclists.org/fulldisclosure/2014/apr/21

Trust: 2.5

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/92352

Trust: 1.7

url:https://nvd.nist.gov/vuln/detail/cve-2013-7286

Trust: 1.5

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2013-7286

Trust: 0.8

url:http://www.securityfocus.com/bid/66633

Trust: 0.6

url:https://www.hackinparis.com/sites/hackinparis.com/files/mdm-hip_2013.pdf

Trust: 0.4

url:https://www.trustmatta.com/advisories/matta-2013-004.txt

Trust: 0.4

url:http://www.mobileiron.com/en/products/advanced-mobile-management/sentry

Trust: 0.3

url:http://www.mobileiron.com/en/solutions/platform-mobile-it

Trust: 0.3

url:https://cwe.mitre.org/data/definitions/522.html

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

url:https://packetstormsecurity.com/files/125990/mobileiron-vsp-sentry-authentication-bypass.html

Trust: 0.1

url:https://www.trustmatta.com

Trust: 0.1

url:https://www.trustmatta.com/network-penetration-testing.html

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2014-1409

Trust: 0.1

url:https://www.trustmatta.com/training.html

Trust: 0.1

url:https://www.trustmatta.com/vulnerability-assessment.html

Trust: 0.1

url:https://<target>/mics/j_spring_security_check

Trust: 0.1

url:https://www.trustmatta.com/advisories/matta-disclosure-policy-01.txt

Trust: 0.1

sources: CNVD: CNVD-2014-03884 // VULMON: CVE-2013-7286 // BID: 66633 // JVNDB: JVNDB-2013-007270 // PACKETSTORM: 125990 // CNNVD: CNNVD-201406-533 // NVD: CVE-2013-7286

CREDITS

Nico Leidecker

Trust: 1.0

sources: BID: 66633 // PACKETSTORM: 125990 // CNNVD: CNNVD-201406-533

SOURCES

db:CNVDid:CNVD-2014-03884
db:VULMONid:CVE-2013-7286
db:BIDid:66633
db:JVNDBid:JVNDB-2013-007270
db:PACKETSTORMid:125990
db:CNNVDid:CNNVD-201406-533
db:NVDid:CVE-2013-7286

LAST UPDATE DATE

2024-11-23T22:37:32.477000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2014-03884date:2014-06-26T00:00:00
db:VULMONid:CVE-2013-7286date:2020-02-25T00:00:00
db:BIDid:66633date:2014-04-02T00:00:00
db:JVNDBid:JVNDB-2013-007270date:2020-03-06T00:00:00
db:CNNVDid:CNNVD-201406-533date:2021-08-02T00:00:00
db:NVDid:CVE-2013-7286date:2024-11-21T02:00:39.553

SOURCES RELEASE DATE

db:CNVDid:CNVD-2014-03884date:2014-06-26T00:00:00
db:VULMONid:CVE-2013-7286date:2020-02-12T00:00:00
db:BIDid:66633date:2014-04-02T00:00:00
db:JVNDBid:JVNDB-2013-007270date:2020-03-06T00:00:00
db:PACKETSTORMid:125990date:2014-04-02T17:22:22
db:CNNVDid:CNNVD-201406-533date:2014-04-02T00:00:00
db:NVDid:CVE-2013-7286date:2020-02-12T18:15:09.987