Junglewise Threat Intelligence

CVE-2016-10140: ZoneMinder authentication bypass and info disclosure in Apache config

CVE-2016-10140 · Severity: high · CVSS 7.5 · Published 2017-01-13

Technologies: Zoneminder. Vendors: Zoneminder.

Executive brief

A security flaw in the bundled web server configuration of ZoneMinder, a popular video surveillance software, allows unauthorized users to browse private server directories. This vulnerability enables remote attackers to view sensitive CCTV images and event recordings without providing a username or password. This could lead to significant privacy breaches and the exposure of monitored physical locations.

Technical details

An information disclosure and authentication bypass vulnerability exists in the bundled Apache HTTP Server configuration for ZoneMinder versions 1.29 and 1.30.0. The flaw stems from the 'Indexes' option being enabled in the default Apache configuration files (e.g., zoneminder.conf), which permits directory listing across the web root. A remote, unauthenticated attacker can exploit this by navigating to specific URIs, such as /events, to bypass intended access controls and view stored surveillance footage and images. The issue was addressed by removing 'Indexes' from the Options directive in the Apache configuration templates.

Affected products

  • ZoneMinder ZoneMinder 1.29, 1.30.0

Timeline

  • 2016-11-08: disclosed: Vendor contacted by researcher
  • 2016-11-22: patched: Fix merged into master branch on GitHub
  • 2017-01-13: advisory: NVD publication date

References

Related threats