Executive brief
Viprinet Multichannel VPN Router 300 is a networking appliance used to provide secure, high-speed internet connectivity. Multiple security flaws in its management interfaces allow attackers to inject malicious scripts that could be executed in the browsers of legitimate administrators. This could lead to unauthorized access to the management console, session hijacking, or the theft of sensitive configuration data.
Technical details
The Viprinet Multichannel VPN Router 300 contains both persistent and reflected cross-site scripting (XSS) vulnerabilities within its 'old' and 'new' web management interfaces. The root cause is a failure to sanitize user-supplied input before storing it or rendering it in the browser. Persistent XSS can be triggered via the username field during login or account creation, and via the device hostname setting; these scripts execute when an administrator views logs or account lists. Reflected XSS exists in the 'inspect', 'commands', and 'host' parameters of the config, atcommands, and ping modules respectively. While the use of session IDs in URLs provides some mitigation against automated reflected attacks, the systemic lack of input validation allows for session hijacking and unauthorized administrative actions. The issues were addressed in firmware versions 2014013131 and 2014020702.
Affected products
- Viprinet Multichannel VPN Router 300 2013070830, 2013080900
Timeline
- 2014-02-03: disclosed: Vulnerability reported by Portcullis Security
- 2014-01-31: patched: First fixed firmware version released
- 2017-01-20: advisory: NVD publication date
References
- http://packetstormsecurity.com/files/135613/Viprinet-Multichannel-VPN-Router-300-Cross-Site-Scripting.html
- http://seclists.org/fulldisclosure/2016/Feb/8
- http://www.securityfocus.com/archive/1/537441/100/0/threaded
- https://www.exploit-db.com/exploits/39407/
- https://www.portcullis-security.com/security-research-and-downloads/security-advisories/cve-2014-2045/