Junglewise Threat Intelligence

CVE-2016-8205: Brocade Network Advisor directory traversal in DashboardFileReceiveServlet

CVE-2016-8205 · Severity: critical · CVSS 9.8 · Published 2017-01-14

Technologies: Brocade Network Advisor. Vendors: Brocade.

Executive brief

Brocade Network Advisor is a management platform used to monitor and configure storage area networks (SANs). A security flaw in the software allows an unauthenticated attacker to upload malicious files to sensitive areas of the server's file system. This could lead to a complete takeover of the management server, potentially disrupting network operations or exposing sensitive configuration data.

Technical details

A directory traversal vulnerability exists within the DashboardFileReceiveServlet component of Brocade Network Advisor. The servlet fails to properly validate user-supplied paths during file upload operations, allowing an attacker to escape the intended directory. By sending a specially crafted request, a remote, unauthenticated attacker can upload arbitrary files to executable locations on the file system. This can be leveraged to achieve remote code execution under the context of the SYSTEM account. The vulnerability is fixed in versions 14.0.3, 14.1.1, and later.

Affected products

  • Brocade Network Advisor Versions prior to and including 14.0.2

Timeline

  • 2016-10-17: other: Vulnerability reported to vendor
  • 2017-01-06: advisory: Initial publication of Brocade security advisory BSA-2017-178
  • 2017-01-14: disclosed: NVD publication date
  • 2017-01-20: advisory: Coordinated public release of ZDI advisory

References

Related threats