Executive brief
Brocade Network Advisor is a management platform used to monitor and configure storage area networks (SANs). A critical security flaw allows an unauthenticated attacker to remotely upload malicious files to the server. This could lead to a complete takeover of the management system, potentially disrupting network operations or allowing unauthorized access to sensitive infrastructure configurations.
Technical details
A directory traversal vulnerability exists in the FileReceiveServlet component of Brocade Network Advisor due to insufficient validation of user-supplied paths during file upload operations. An unauthenticated remote attacker can exploit this by sending a specially crafted request to upload a malicious file (such as a web shell) into a directory where it can be executed. Successful exploitation allows for arbitrary code execution with SYSTEM privileges. The vulnerability is fixed in Brocade Network Advisor versions 14.0.3, 14.1.1, and later.
Affected products
- Brocade Network Advisor Versions up to and including 14.0.2
Timeline
- 2016-10-17: disclosed: Vulnerability reported to vendor via ZDI
- 2017-01-06: advisory: Initial vendor advisory published by Brocade
- 2017-01-14: advisory: NVD publication date