Full Disclosure mailing list archives

Programi Bilanc - Build 007 Release 014 31.01.2020 - Broken encryption with guessable static encryption key [CVE-2020-8995]


From: Georg Ph E Heise via Fulldisclosure <fulldisclosure () seclists org>
Date: Thu, 17 Dec 2020 11:51:36 +0000

Programi Bilanc - Build 007 Release 014 31.01.2020 - Broken encryption with guessable static encryption key

===============================================================================

Identifiers

-------------------------------------------------

CVE-2020-8995

Vendor

-------------------------------------------------

Balanc Shpk (https://bilanc.com)

Product

-------------------------------------------------

Programi Bilanc

Affected versions

-------------------------------------------------

- Programi Bilanc - Build 007 Release 014 31.01.2020 and possibly below

Credit

-------------------------------------------------

Georg Ph E Heise (@gpheheise) / Lufthansa Industry Solutions (@LHIND_DLH)

Vulnerability summary

-------------------------------------------------

Programi Bilanc Build 007 Release 014 31.01.2020 supplies a .exe file containing several hardcoded credentials to 
different servers that allow remote attackers to gain access to the complete infrastructure including the website, 
update server, and external issue tracking tools.

Technical details

------------------------------------------------

To exploit this vulnerability an attack has to gain access to the Windows .exe

Proof of concept

-------------------------------------------------

Withheld

Solution

-------------------------------------------------

Don’t use the software in its current version & contact vendor for a solution

Timeline

-------------------------------------------------

Date| Status

------------|--------------------

01–APR-2020 | Reported to vendor

30-JUN-2020 | End of 90 days Full Disclosure Time

17-DEZ-2020 | FULL disclosure

_______________________________________________
Sent through the Full Disclosure mailing list
https://nmap.org/mailman/listinfo/fulldisclosure
Web Archives & RSS: http://seclists.org/fulldisclosure/

Current thread: