BridgeHead FileStore versions prior to 24A (released in early 2024) expose the Apache Axis2 administration module on network-accessible endpoints with default credentials that allows unauthenticated remote attackers to execute arbitrary OS commands. Attackers can authenticate to the admin console using default credentials, upload a malicious Java archive as a web service, and execute arbitrary commands on the host via SOAP requests to the deployed service.
The attacker connects remotely to the Apache Axis2 administrative interface, which is accessible over the network and configured with default credentials. After authenticating using these default credentials, the attacker uploads a malicious Java archive (JAR) as a web service. Subsequently, using SOAP requests to the deployed service, the attacker executes arbitrary commands on the host server. The vulnerability results from two weaknesses: an unsecured default configuration (CWE-1188) and the use of weak or default authentication credentials (CWE-1391).
The attacker gains the ability to execute arbitrary operating system commands on the server with the privileges of the service process, which can lead to complete system takeover, data theft, and further lateral movement within the network.
BridgeHead FileStore should be updated to version 24A or later. Additionally, regardless of the update, default credentials for the Apache Axis2 administrative module must be changed immediately, and network access to the administrative interface should be restricted to trusted IP addresses only using firewall or network rules.
BridgeHead FileStore in versions prior to 24A (released in early 2024)
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X