[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[FD] Security advisory: Pre-authentication RCE (SQL injection) in XPressEntry 3.7.7454 (Telaeris Inc)



0day Rubbish Research Team is publicly disclosing a vulnerability in 
XPressEntry 3.7.7454 (Telaeris Inc). The research is published and a 
proof-of-concept is available.

Pre-authentication RCE (SQL injection) (CVSS 9.8, pre-authentication)

Telaeris XPressEntry 3.7.7454 runs its main HTTP API without authentication 
when RequireReaderCredentials is False, which is the default. The 
SaveVerifyActivity handler concatenates the sNotes parameter into an INSERT 
statement with no escaping. On a SQL Server backend with a sysadmin application 
account, an unauthenticated attacker uses a COMMIT-breakout payload to enable 
xp_cmdshell and execute arbitrary commands as LocalSystem. Dynamically verified.

Impact: Full compromise of the physical access-control and emergency-mustering 
system as LocalSystem. The attacker can alter badge records, forge or block 
entry events, and take over facility-security infrastructure.

Advisory: 
https://0day-rubbish.com/blog/telaeris-xpressentry-unauth-sqli-xpcmdshell-rce

PoC and full analysis: https://github.com/Exploit-Garbage/0day-Rubbish

Vendor has been notified. CVE ID is pending.

-- 
0day Rubbish Research Team
https://0day-rubbish.com
_______________________________________________
Sent through the Full Disclosure mailing list
https://nmap.org/mailman/listinfo/fulldisclosure
Web Archives & RSS: https://seclists.org/fulldisclosure/