Executive brief
Brocade Network Advisor, a management platform for storage area networks (SAN), contains a flaw that allows unauthorized users to manipulate files on the system. An attacker can remotely delete critical system files or overwrite data, potentially leading to a complete service outage or loss of management capabilities. This vulnerability poses a significant risk to the availability and integrity of the network management infrastructure.
Technical details
A directory traversal vulnerability exists within the SoftwareImageUpload servlet of Brocade Network Advisor due to insufficient validation of user-supplied paths. A remote, unauthenticated attacker can exploit this by sending specially crafted requests to the servlet, allowing them to perform file operations outside of the intended directory. This can be leveraged to overwrite or delete arbitrary files with SYSTEM-level privileges on the host. The vulnerability is addressed in Brocade Network Advisor versions 14.0.3, 14.1.1, and later.
Affected products
- Brocade Network Advisor Versions prior to and including 14.0.2
Timeline
- 2016-10-17: disclosed: Vulnerability reported to vendor via ZDI
- 2017-01-06: advisory: Initial Broadcom/Brocade advisory published (BSA-2017-179)
- 2017-01-14: other: NVD publication date
- 2017-01-20: other: ZDI advisory published