Junglewise Threat Intelligence

CVE-2016-6603: Zoho WebNMS Framework authentication bypass via UserName header

CVE-2016-6603 · Severity: critical · CVSS 9.8 · Published 2017-01-23

Vendors: Zoho.

Executive brief

Zoho WebNMS Framework, a platform used by telecommunications and network providers to build management systems, contains a critical flaw that allows anyone to take over administrative accounts. By simply sending a specially crafted web request, an attacker can impersonate any user, including the 'root' administrator, without needing a password. This could lead to full control over the network management system and any connected infrastructure.

Technical details

The vulnerability exists in the GetChallengeServlet component of Zoho WebNMS Framework. An unauthenticated remote attacker can impersonate any valid user, including the 'root' superuser, by providing a target username in the 'UserName' HTTP header of a request to the servlet. The server responds with a valid authenticated JSESSIONID cookie for that user. This session cookie can then be used to access the WebNMS Framework Server with the privileges of the impersonated account. At the time of disclosure, the vendor had not responded to reports, and no official patch was confirmed.

Affected products

  • Zoho WebNMS Framework 5.2, 5.2 SP1

Timeline

  • 2016-07-04: disclosed: Initial discovery and disclosure to vendor via SSD program
  • 2016-08-08: advisory: Public advisory released by security researcher
  • 2017-01-23: advisory: NVD publication date

References