Junglewise Threat Intelligence

CVE-2016-8207: Brocade Network Advisor directory traversal in CliMonitorReportServlet

CVE-2016-8207 · Severity: high · CVSS 7.5 · Published 2017-01-14

Technologies: Brocade Network Advisor. Vendors: Brocade.

Executive brief

Brocade Network Advisor, a management platform for storage area networks (SAN), contains a security flaw that allows unauthorized individuals to access files on the server. By exploiting this vulnerability, an attacker could remotely steal sensitive configuration data or user information without needing a password. This could lead to a significant breach of confidentiality and provide a foothold for further attacks on the network infrastructure.

Technical details

A directory traversal vulnerability exists within the CliMonitorReportServlet of Brocade Network Advisor due to insufficient validation of user-supplied input used in file path operations. An unauthenticated remote attacker can exploit this by sending specially crafted HTTP requests containing path traversal sequences (e.g., ../) to access files outside of the intended web directory. Successful exploitation allows the disclosure of sensitive information under the context of the SYSTEM account. The vulnerability is fixed in Brocade Network Advisor versions 14.0.3, 14.1.1, and all subsequent releases.

Affected products

  • Brocade Network Advisor Versions prior to and including 14.0.2

Timeline

  • 2016-10-17: disclosed: Vulnerability reported to vendor via ZDI
  • 2017-01-06: patched: Initial vendor advisory published by Brocade
  • 2017-01-14: advisory: NVD published CVE-2016-8207

References

Related threats