CVE-2015-0932

The ANTlabs InnGate firmware on IG 3100, IG 3101, InnGate 3.00 E, InnGate 3.01 E, InnGate 3.02 E, InnGate 3.10 E, InnGate 3.01 G, and InnGate 3.10 G devices does not require authentication for rsync sessions, which allows remote attackers to read or write to arbitrary files via TCP traffic on port 873.
Configurations

Configuration 1 (hide)

OR cpe:2.3:h:antlabs:inngate_ig_3.00_e:*:*:*:*:*:*:*:*
cpe:2.3:h:antlabs:inngate_ig_3.01_e:*:*:*:*:*:*:*:*
cpe:2.3:h:antlabs:inngate_ig_3.02_e:*:*:*:*:*:*:*:*
cpe:2.3:h:antlabs:inngate_ig_3.10_e:*:*:*:*:*:*:*:*
cpe:2.3:h:antlabs:inngate_ig_3.10_g:*:*:*:*:*:*:*:*
cpe:2.3:h:antlabs:inngate_ig_3100:*:*:*:*:*:*:*:*
cpe:2.3:h:antlabs:inngate_ig_3101:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2015-04-05 01:59

Updated : 2024-02-04 18:35


NVD link : CVE-2015-0932

Mitre link : CVE-2015-0932

CVE.ORG link : CVE-2015-0932


JSON object : View

Products Affected

antlabs

  • inngate_ig_3100
  • inngate_ig_3.00_e
  • inngate_ig_3.10_e
  • inngate_ig_3.01_e
  • inngate_ig_3101
  • inngate_ig_3.02_e
  • inngate_ig_3.10_g
CWE
CWE-264

Permissions, Privileges, and Access Controls