{"id":58542,"date":"2024-07-30T18:41:11","date_gmt":"2024-07-30T15:41:11","guid":{"rendered":"https:\/\/packetstormsecurity.com\/files\/179815\/sanncesmart-disclose.txt"},"modified":"2024-07-30T18:41:11","modified_gmt":"2024-07-30T15:41:11","slug":"sannce-smart-hd-wifi-security-camera-ean-2-950004-595317-weak-hashing-disclosure","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/sannce-smart-hd-wifi-security-camera-ean-2-950004-595317-weak-hashing-disclosure\/","title":{"rendered":"Sannce Smart HD Wifi Security Camera EAN 2 950004 595317 Weak Hashing \/ Disclosure"},"content":{"rendered":"[Suggested description]An issue was discovered on Sannce Smart HD Wifi Security Camera EAN 2 950004 595317 devices.<br \/>A local attacker with the &#8220;default&#8221; account is capable of reading the<br \/>\/etc\/passwd file, which contains a weakly hashed root password.<br \/>By taking this hash and cracking it, the attacker<br \/>can obtain root rights on the device.<\/p>\n<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;<\/p>\n[Vulnerability Type]Insecure Permissions<\/p>\n<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;<\/p>\n[Vendor of Product]Sannce<\/p>\n<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;<\/p>\n[Affected Product Code Base]Sannce Smart HD Wifi Security Camera &#8211; EAN nr: 2 950004 595317<\/p>\n<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;<\/p>\n[Affected Component]Root user through file \/etc\/passwd<\/p>\n<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;<\/p>\n[Attack Type]Local<\/p>\n<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;<\/p>\n[Impact Escalation of Privileges]true<\/p>\n<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;<\/p>\n[Attack Vectors]To exploit the vulnerability, someone must be able to get local<br \/>presence on the device. e.g. through command injection or by using the<br \/>telnet interface as a low-privileged user.<\/p>\n<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;<\/p>\n[Has vendor confirmed or acknowledged the vulnerability?]true<\/p>\n<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;<\/p>\n[Discoverer]Willem Westerhof, Jasper Nota, Martijn Baalman from Qbit cyber security in cooperation with the Dutch Consumer organisation.<\/p>\n<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;<\/p>\n[Reference]https:\/\/www.sannce.com<\/p>\n<p>Use CVE-2019-20466.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>[Suggested description]An issue was discovered on Sannce Smart HD Wifi Security Camera EAN 2 950004 595317 devices.A local attacker with the &#8220;default&#8221; account is capable of reading the\/etc\/passwd file, which contains a weakly hashed root password.By taking this hash and cracking it, the attackercan obtain root rights on the device. &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212; [Vulnerability Type]Insecure Permissions &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212; &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-58542","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/58542","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=58542"}],"version-history":[{"count":0,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/58542\/revisions"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=58542"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=58542"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=58542"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}