W aplikacji Versa Director wykryto podatność typu command injection (CWE-77), pozwalającą atakującemu na zdalne wykonanie dowolnych poleceń systemowych. Podatność jest krytyczna ze względu na brak wymagania uwierzytelnienia oraz pełny wpływ na poufność, integralność i dostępność systemu.
▸ Pokaż oryginał (EN)
In Versa Director, the command injection is an attack in which the goal is execution of arbitrary commands on the host operating system via a vulnerable application. Command injection attacks are possible when an application passes unsafe user supplied data (forms, cookies, HTTP headers etc.) to a system shell. In this attack, the attacker-supplied operating system commands are usually executed with the privileges of the vulnerable application. Command injection attacks are possible largely due to insufficient input validation.
Podatność wynika z niewystarczającej walidacji danych wejściowych dostarczanych przez użytkownika (np. poprzez formularze, ciasteczka lub nagłówki HTTP). Aplikacja przekazuje niezaufane dane bezpośrednio do powłoki systemowej (shell), co umożliwia wstrzyknięcie i wykonanie dowolnych poleceń systemu operacyjnego. Wstrzyknięte polecenia są wykonywane z uprawnieniami procesu aplikacji Versa Director.
Atakujący może przejąć pełną kontrolę nad systemem operacyjnym hosta, w tym uzyskać dostęp do poufnych danych, modyfikować konfigurację systemu oraz doprowadzić do jego niedostępności.
Należy zastosować patche dostępne u producenta zgodnie z referencjami. Dodatkowo zaleca się ograniczenie dostępu sieciowego do interfejsu Versa Director wyłącznie do zaufanych adresów IP oraz wdrożenie reguł firewall blokujących nieautoryzowany dostęp.
Versa Networks Versa Director — wersje wskazane w referencjach producenta
Szczegóły techniczne podatności zostały opublikowane w raporcie na platformie HackerOne (raport #1168198).
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HVersa Networks Versa Director
APPVersa-Networks< 16.1R2S1120.2.0 – 20.2.2 (bez)21.1.0 – 21.1.1 (bez)21.2.0 – 21.2.1 (bez)
Powiązane podatności
The Versa Director GUI provides an option to customize the look and feel of the user interface. This option is...
The Versa Director SD-WAN orchestration platform provides an option to upload various types of files. The Vers...
The Versa Director SD-WAN orchestration platform implements Two-Factor Authentication (2FA) using One-Time Pas...
The Versa Director offers REST APIs for orchestration and management. By design, certain APIs, such as the log...
A XSS vulnerability exists in Versa Director Release: 16.1R2 Build: S8. An attacker can use the administration...