CERT-In Vulnerability Note
CIVN-2023-0119
Default Credential Vulnerability in GajShield Data Security Firewall
Original Issue Date:April 26, 2023
Severity Rating: CRITICAL
Software Affected
- GajShield Data Security Firewall- all firmware versions prior to v4.28 except v4.21
Overview
A vulnerability has been identified in GajShield Data Security Firewall (all firmware versions prior to v4.28 except v4.21) which could allow remote attacker to execute arbitrary commands with administrative privileges on the targeted systems.
Description
The vulnerability exists in GajShield Data Security Firewall firmware versions prior to v4.28 (except v4.21) due to insecure default credentials which allows remote attacker to login as superuser by using default username/password via web-based management interface and/or exposed SSH port thereby enabling remote attackers to execute arbitrary commands with administrative/superuser privileges on the targeted systems.
The vulnerability has been addressed by forcing the user to change their default password to a new non-default password.
Note: This vulnerability (CVE-2023-1778) is being exploited in the wild. Users are advised to update the firmware urgently.
Credit: This vulnerability is identified by Prashant Pandey from Indian Computer Emergency Response Team (CERT-In).
Solution
Update GajShield Data Security Firewall firmware to latest version
https://kb.gajshield.com/kbarticle?entryid=299&parentid=35
https://kb.gajshield.com/kbarticle?entryid=318&parentid=35
Vendor Information
GajShield
https://kb.gajshield.com/kbarticle?entryid=299&parentid=35
https://kb.gajshield.com/kbarticle?entryid=318&parentid=35
References
GajShield
https://kb.gajshield.com/kbarticle?entryid=299&parentid=35
https://kb.gajshield.com/kbarticle?entryid=318&parentid=35
CVE Name
CVE-2023-1778
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|