HTTP: AVTECH Room Alert 3E Privilege Escalation

This signature detects attempts to exploit a known vulnerability against AVTECH Room Alert 3E. A successful attack can lead to elevation of privilege and arbitrary code execution.

Extended Description

On AVTECH Room Alert 3E devices before 2.2.5, an attacker with access to the device's web interface may escalate privileges from an unauthenticated user to administrator by performing a cmd.cgi?action=ResetDefaults&src=RA reset and using the default credentials to get in.

References

CVE: CVE-2019-13379

Short Name
HTTP:CTS:AVTECH-ROOMALRT-3E-PE
Severity
Critical
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
3E AVTECH Alert CVE-2019-13379 Escalation Privilege Room
Release Date
08/27/2020
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3415
False Positive
Unknown
CVSS Score

9.0

Found a potential security threat?