« Volver al listado

CVE-2019-12254

Estado: ModificadaCrítica (9.8)—

In multiple Tecson Tankspion and GOKs SmartBox 4 products the affected application doesn't properly restrict access to an endpoint that is responsible for saving settings, to a unauthenticated user with limited access rights. Based on the lack of adequately implemented access-control rules, by accessing a specific uniform resource locator (URL) on the web server, a malicious user is able to change the application settings without authenticating at all, which violates originally laid ACL rules.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (5)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2019-12254",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 10,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "LOW",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "info@cert.vde.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "info@cert.vde.com",
      "affectedData": [
        {
          "vendor": "TECSON",
          "product": "e-litro net",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "V6.32",
              "versionType": "custom"
            }
          ]
        },
        {
          "vendor": "TECSON",
          "product": "LX-Net",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "V6.32",
              "versionType": "custom"
            }
          ]
        },
        {
          "vendor": "TECSON",
          "product": "LX-Q-Net",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "V6.32",
              "versionType": "custom"
            }
          ]
        },
        {
          "vendor": "GOK",
          "product": "SmartBox 4 LAN",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "V6.3",
              "versionType": "custom"
            }
          ]
        },
        {
          "vendor": "GOK",
          "product": "SmartBox 4 LAN PRO",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "V6.3",
              "versionType": "custom"
            }
          ]
        }
      ]
    }
  ],
  "published": "2022-05-06T18:15:08.397",
  "references": [
    {
      "url": "https://cert.vde.com/en/advisories/VDE-2019-012/",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "info@cert.vde.com"
    },
    {
      "url": "https://cert.vde.com/en/advisories/VDE-2019-012/",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "info@cert.vde.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-287"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "In multiple Tecson Tankspion and GOKs SmartBox 4 products the affected application doesn't properly restrict access to an endpoint that is responsible for saving settings, to a unauthenticated user with limited access rights. Based on the lack of adequately implemented access-control rules, by accessing a specific uniform resource locator (URL) on the web server, a malicious user is able to change the application settings without authenticating at all, which violates originally laid ACL rules."
    },
    {
      "lang": "es",
      "value": "En varios productos Tecson Tankspion y GOKs SmartBox 4, la aplicación afectada no restringe apropiadamente el acceso a un endpoint que es responsable de guardar la configuración, a un usuario no autenticado con derechos de acceso limitados. Basándose en la falta de reglas de control de acceso adecuadamente implementadas, al acceder a un localizador uniforme de recursos (URL) específico en el servidor web, un usuario malicioso es capaz de cambiar la configuración de la aplicación sin autenticarse en absoluto, lo que viola las reglas ACL originalmente establecidas"
    }
  ],
  "lastModified": "2026-06-17T02:14:18.553",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:gok:smartbox_4_lan_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4C9385EB-5444-400B-8E50-D2BE1813EFD1"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:gok:smartbox_4_lan:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "7F9081DF-4A88-4693-9F02-0554C3DBE67E"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:gok:smartbox_4_lan_pro_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E666749C-0320-493E-B4FB-25E52D376F6F"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:gok:smartbox_4_lan_pro:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "A7BBB65A-A593-43EE-A781-56D837C5C904"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:tecson:lx-q-net_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BC2D7550-F679-40C8-84FE-D26450F0006F"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:tecson:lx-q-net:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "CA2F641C-4883-460E-8B49-DE793C495961"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:tecson:lx-net_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4749C693-6D51-4067-9B52-9A03811D4F35"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:tecson:lx-net:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "9692F473-3325-4EE5-9EA3-CD8975B260AC"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:tecson:e-litro_net_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "355A7726-E136-4AB5-A09C-862D42A1B2E3"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:tecson:e-litro_net:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "AFFDE7D6-E2EF-40C3-B44A-7516A3F13703"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "info@cert.vde.com"
}