{"id":60594,"date":"2024-12-04T00:11:34","date_gmt":"2024-12-03T21:11:34","guid":{"rendered":"https:\/\/packetstormsecurity.com\/files\/182932\/paxtonnet2-disclose.txt"},"modified":"2024-12-04T00:11:34","modified_gmt":"2024-12-03T21:11:34","slug":"paxton-net2-information-disclosure-incorrect-access-control","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/paxton-net2-information-disclosure-incorrect-access-control\/","title":{"rendered":"Paxton Net2 Information Disclosure \/ Incorrect Access Control"},"content":{"rendered":"<p>CloudAware Security Advisory<\/p>\n[CVE pending]: Potential PII leak and incorrect access control in Paxton <br \/>Net2 software<\/p>\n<p>========================================================================<br \/>Summary<br \/>========================================================================<br \/>Insecure backend database in the Paxton Net2 software. Possible leaking <br \/>of PII incorrect access control.<br \/>No physical access to computer running Paxton Net2 is required.<\/p>\n<p>========================================================================<br \/>Product<br \/>========================================================================<br \/>* Paxton Net2&nbsp; (all current versions)<\/p>\n<p>========================================================================<br \/>Detailed description<br \/>========================================================================<br \/>By exploiting MSSQL single usermode it is possible to gain administrator <br \/>rights to the Net2 database. In this database<br \/>plaintext PIN codes for building entrance can be found and changed. It <br \/>is also possible to add users to the system and<br \/>enable\/disable users in the system. By reading tables in the MSSQL table <br \/>PII is leaked. In order to gain access local<br \/>access to the computer running Net2 is necessary, but this can also be <br \/>over a network using e.g. Anydesk which makes<br \/>physical access not necessary.<br \/>The vendor has not acknowledged the vulnerability after contact. There <br \/>is no fix planned.<\/p>\n<p>========================================================================<br \/>Solution<br \/>========================================================================<br \/>As the vendor has not acknowledged the vulnerability there is no <br \/>effective remediation for this vulnerability.<br \/>The most effective measure at this moment is closely monitoring who has <br \/>local access to the machine running the Net2<br \/>software.<\/p>\n<p>========================================================================<br \/>Mitigation<br \/>========================================================================<br \/>There is no known effective mitigation. Limiting who has local access to <br \/>the machine running the Net2 software seems<br \/>the most effective measure.<\/p>\n<p>========================================================================<br \/>Weblinks<br \/>========================================================================<br \/>It has been decided not to release the exploit code yet as there is no <br \/>mitigration possible. Discoverers are willing to<br \/>share exploit code at request to help with mitigration.<\/p>\n<p>========================================================================<br \/>Discoverers<br \/>========================================================================<br \/>Jeroen Hermans, CloudAware j.hermans[at]cloudaware[dot]eu<br \/>Emiel van Berlo, Danego emiel[at]danego[dot]nl<\/p>\n<p>========================================================================<br \/>History<br \/>========================================================================<br \/>Nov 12 2024: Requested latest Net2 software from Paxton<br \/>Nov 26, 2024: Obtained latest Net2 software for other source<br \/>Nov 26, 2024: Informed Paxton about vulnerability<br \/>Nov 27, 2024: Release of exploit code<br \/>Dec 2, 2024: Refused CVE reservation by Paxton &amp; request of CVE <br \/>reservation directly at Mitre<\/p>\n","protected":false},"excerpt":{"rendered":"<p>CloudAware Security Advisory [CVE pending]: Potential PII leak and incorrect access control in Paxton Net2 software ========================================================================Summary========================================================================Insecure backend database in the Paxton Net2 software. Possible leaking of PII incorrect access control.No physical access to computer running Paxton Net2 is required. ========================================================================Product========================================================================* Paxton Net2&nbsp; (all current versions) ========================================================================Detailed description========================================================================By exploiting MSSQL single usermode it is possible &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-60594","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/60594","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=60594"}],"version-history":[{"count":0,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/60594\/revisions"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=60594"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=60594"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=60594"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}