Junglewise Threat Intelligence

CVE-2016-6484: Infoblox NetMRI CRLF injection in login component

CVE-2016-6484 · Severity: medium · CVSS 6.1 · Published 2017-01-23

Executive brief

Infoblox NetMRI, a tool used for automating network management and configuration, is vulnerable to a security flaw in its login interface. An attacker can trick a user's browser into receiving manipulated web traffic, which could lead to the theft of sensitive session information or the display of fraudulent content. This could compromise the integrity of the network management console and lead to unauthorized access.

Technical details

A CRLF injection vulnerability exists in Infoblox Network Automation NetMRI versions prior to 7.1.1. The flaw is located in the 'contentType' parameter of the login action at 'config/userAdmin/login.tdf'. By injecting Carriage Return and Line Feed (CRLF) characters, a remote attacker can perform HTTP response splitting. This allows for the injection of arbitrary HTTP headers or the hijacking of the HTTP response body. Successful exploitation typically requires some user interaction (such as clicking a malicious link) and can result in cross-site scripting (XSS), cache poisoning, or session hijacking. The issue was addressed in version 7.1.1.

Affected products

  • Infoblox Network Automation NetMRI before 7.1.1

Timeline

  • 2016-09-06: disclosed: Initial public disclosure via security mailing lists
  • 2017-01-23: advisory: NVD publication date

References