Executive brief
Zoho WebNMS Framework, a platform used by telecommunications and service providers to build network management systems, contains a security flaw in its file download feature. An unauthorized attacker can exploit this to read sensitive files from the server's operating system. This could lead to the exposure of configuration data, system credentials, or other confidential information, potentially allowing for further compromise of the network management infrastructure.
Technical details
A directory traversal vulnerability exists in the FetchFile servlet of Zoho WebNMS Framework versions 5.2 and 5.2 SP1. The 'fileName' parameter in the /servlets/FetchFile endpoint does not properly sanitize input, allowing an unauthenticated remote attacker to use 'dot-dot-slash' (../) sequences to access files outside of the intended directory. While the vulnerability is limited to text-based files (binary files may be corrupted during download), it can be used to retrieve sensitive system files such as /etc/shadow or the application's own security configuration files containing obfuscated credentials. No patch was confirmed by the vendor at the time of disclosure; mitigation involves restricting network access to the server.
Affected products
- Zoho WebNMS Framework 5.2, 5.2 SP1
Timeline
- 2016-07-04: disclosed: Initial discovery and disclosure to vendor via SSD program
- 2016-08-08: advisory: Public advisory released by researcher
- 2017-01-23: disclosed: NVD publication date
References
- http://packetstormsecurity.com/files/138244/WebNMS-Framework-5.2-SP1-Traversal-Weak-Obfuscation-User-Impersonation.html
- http://seclists.org/fulldisclosure/2016/Aug/54
- http://www.rapid7.com/db/modules/auxiliary/admin/http/webnms_cred_disclosure
- http://www.rapid7.com/db/modules/auxiliary/admin/http/webnms_file_download
- http://www.securityfocus.com/archive/1/539159/100/0/threaded
- http://www.securityfocus.com/bid/92402
- https://blogs.securiteam.com/index.php/archives/2712