{"id":60450,"date":"2024-11-23T04:31:51","date_gmt":"2024-11-23T01:31:51","guid":{"rendered":"https:\/\/packetstormsecurity.com\/files\/182759\/UAS-20241118-0.txt"},"modified":"2024-11-23T04:31:51","modified_gmt":"2024-11-23T01:31:51","slug":"seh-utnserver-pro-20-1-22-cross-site-scripting","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/seh-utnserver-pro-20-1-22-cross-site-scripting\/","title":{"rendered":"SEH utnserver Pro 20.1.22 Cross Site Scripting"},"content":{"rendered":"<p>St. P\u00f6lten UAS 20241118-0<br \/>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br \/>title| Multiple Stored Cross-Site Scripting<br \/>product| SEH utnserver Pro<br \/>vulnerable version| 20.1.22<br \/>fixed version| 20.1.35<br \/>CVE number| CVE-2024-11304<br \/>impact| High<br \/>homepage| https:\/\/www.seh-technology.com\/<br \/>found| 2024-05-24<br \/>by| P. Riedl, J. Springer, P. Chist\u00e8, D. Sagl, S. Vogt<br \/>| These vulnerabilities were discovery during research at<br \/>| St.P\u00f6lten UAS, supported and coordinated by CyberDanube.<br \/>|<br \/>| https:\/\/fhstp.ac.at | https:\/\/cyberdanube.com<br \/>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<\/p>\n<p>Vendor description<br \/>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br \/>&#8220;We are SEH from Bielefeld &#8211; manufacturer of high-quality network solutions.<br \/>With over 35 years of experience in the fields of printing and networks, we<br \/>offer our customers a broad and high-level expertise in solutions for all types<br \/>of business environments.&#8221;<\/p>\n<p>Source: https:\/\/www.seh-technology.com\/us\/company\/about-us.html<\/p>\n<p>Vulnerable versions<br \/>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br \/>utnserver Pro \/ 20.1.22<br \/>utnserver ProMAX \/ 20.1.22<br \/>INU-100 \/ 20.1.22<\/p>\n<p>Vulnerability overview<br \/>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br \/>1) Multiple Stored Cross-Site Scripting (CVE-2024-11304)<br \/>Different settings on the web interface of the device can be abused to store<br \/>JavaScript code and execute it in the context of a user&#8217;s browser.<\/p>\n<p>Proof of Concept<br \/>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br \/>1) Multiple Stored Cross-Site Scripting (CVE-2024-11304)<br \/>The following snippet can be used to demonstrate, that stored cross-site<br \/>scripting is possible in multiple locations on the device:<br \/>&#8220;&gt;&lt;script&gt;alert(document.location)&lt;\/script&gt;<\/p>\n<p>Examples are:<br \/>* Users password: &#8220;usrMg_pwd&#8221;<br \/>This can be displayed in cleartext and executed in the device configuration.<br \/>* Certificate options: &#8220;Common name&#8221;, &#8220;Organization name&#8221;, &#8220;Locality name&#8221;<br \/>This can be executed in the certificate information.<br \/>* Device description: &#8220;Host name&#8221;, &#8220;Contact person&#8221;, &#8220;Description&#8221;<br \/>This can be executed in &#8220;Device -&gt; Description&#8221;.<br \/>* USB password via uploading a crafted &#8220;_parameters.txt&#8221; file: &#8220;usbMdg_pwd&#8221;<br \/>This can be executed in the &#8220;Maintenance -&gt; Content View&#8221; tab.<\/p>\n<p>Saving this text to the device description leads to a persistent cross-site<br \/>scripting. Therefore, everyone who openes the device description executes the<br \/>injected code in the context of the own browser.<\/p>\n<p>The vulnerabilities were manually verified on an emulated device by using the<br \/>MEDUSA scalable firmware runtime (https:\/\/medusa.cyberdanube.com).<\/p>\n<p>Solution<br \/>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br \/>Install firmware version 20.1.35 to fix the vulnerabilities.<\/p>\n<p>Workaround<br \/>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br \/>None<\/p>\n<p>Recommendation<br \/>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br \/>CyberDanube recommends SEH Computertechnik customers to upgrade the firmware to<br \/>the latest version available.<\/p>\n<p>Contact Timeline<br \/>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br \/>2024-09-23: Contacting SEH Computertechnik and sent advisory to support.<br \/>Support answered, that vulnerabilities are fixed in version<br \/>20.1.35.<br \/>2024-10-21: Closed the issue and scheduled publication for November.<br \/>2024-11-18: Coordinated disclosure of advisory.<\/p>\n<p>Web: https:\/\/www.fhstp.ac.at\/<br \/>Twitter: https:\/\/x.com\/fh_stpoelten<br \/>Mail: mis@fhstp.ac.at<\/p>\n<p>EOF T. Weber \/ @2024<\/p>\n","protected":false},"excerpt":{"rendered":"<p>St. P\u00f6lten UAS 20241118-0&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-title| Multiple Stored Cross-Site Scriptingproduct| SEH utnserver Provulnerable version| 20.1.22fixed version| 20.1.35CVE number| CVE-2024-11304impact| Highhomepage| https:\/\/www.seh-technology.com\/found| 2024-05-24by| P. Riedl, J. Springer, P. Chist\u00e8, D. Sagl, S. Vogt| These vulnerabilities were discovery during research at| St.P\u00f6lten UAS, supported and coordinated by CyberDanube.|| https:\/\/fhstp.ac.at | https:\/\/cyberdanube.com&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;- Vendor description&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-&#8220;We are SEH from Bielefeld &#8211; manufacturer &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-60450","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/60450","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=60450"}],"version-history":[{"count":0,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/60450\/revisions"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=60450"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=60450"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=60450"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}