Overview
Emerson Network Power Avocent MergePoint Unity 2016 KVM and possibly other model switches running firmware version 1.9.16473 and possibly previous versions contain a directory traversal vulnerability (CWE-23).
Description
CWE-23: Relative Path Traversal Emerson Network Power Avocent MergePoint Unity 2016 (MPU2016) KVM and possibly other model switches running firmware version 1.9.16473 and possibly previous versions contain a directory traversal vulnerability. This vulnerability is caused from a failure to sanitize the user-supplied input parameter "filename" within the download.php file. An attacker can use directory traversal to download critical files such as /etc/passwd to obtain the credentials for the device.
|
Impact
A remote authenticated attacker can download the configuration files of the device and use the obtained administrator credentials to access the interface. The attacker may then modify the settings of the device with unrestricted access. |
Solution
Update |
Restrict access to the KVM switch interface |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | 4 | AV:N/AC:L/Au:S/C:P/I:N/A:N |
Temporal | 2.8 | E:POC/RL:OF/RC:UC |
Environmental | 0.9 | CDP:L/TD:L/CR:ND/IR:ND/AR:ND |
References
- http://www.emersonnetworkpower.com/en-US/Products/InfrastructureManagement/DigitalKVMAppliances/Pages/AvocentMergePointUnityAppliances.aspx
- http://www.avocent.com/Support_Firmware/MergePoint_Unity/MergePoint_Unity_Switch.aspx
- http://cwe.mitre.org/data/definitions/23.html
- http://www.avocent.com/Support_Firmware/MergePoint_Unity/MergePoint_Unity_Switch_-_Previous_Releases.aspx
Acknowledgements
Thanks to Shady Liu (Shady.liu@dbappsecurity.com.cn) of DBAppSecurity Co.Ltd for reporting this vulnerability and Alfredo Ramirez for providing additional vulnerability information.
This document was written by Adam Rauf.
Other Information
CVE IDs: | CVE-2013-6030 |
Date Public: | 2014-01-23 |
Date First Published: | 2014-01-23 |
Date Last Updated: | 2014-02-07 14:26 UTC |
Document Revision: | 37 |