看板 Bugtraq 關於我們 聯絡資訊
SEC Consult Vulnerability Lab Security Advisory < 20130507-0 > =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D title: Multiple vulnerabilities product: NetApp OnCommand System Manager vulnerable version: <=3D 2.1 and <=3D2.0.2 fixed version: 2.2 (only XSS fixed) CVE: CVE-2013-3320 (XSS) CVE-2013-3321 (File inclusion) CVE-2013-3322 (OS command execution) impact: medium homepage: http://www.netapp.com/ found: 2012-11-06 by: M. Heinzl SEC Consult Vulnerability Lab https://www.sec-consult.com/ =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D Vendor description: ------------------- "You don't need to be a storage expert to manage NetApp storage systems. Configuration and ongoing storage management are easy using the Web-based OnCommand=C2=AE System Manager. System Manager is the simple yet powerful management solution for NetApp storage it'seasy for small to midsize businesses to use and efficient for large enterprises and service providers= .." Source:=20 http://www.netapp.com/us/products/management-software/system-manager.html Vulnerability overview/description: ----------------------------------- NetApp OnCommand System Manager suffers from multiple permanent and reflect= ive=20 cross-site scripting vulnerabilities, a local file inclusion vulnerability = as=20 well as an OS command execution vulnerability. Malicious, authenticated users can exploit these flaws to change the conten= ts=20 of the displayed site, redirect the user to other sites, steal user=20 credentials, execute system commands and read sensitive information. The vendor will not fix the file inclusion and OS command execution issues, as it is considered a design feature.=20 Proof of concepts: ----------------- 1) Multiple Reflective Cross-Site Scripting Vulnerabilities (internal bug=20 number 654355) - CVE-2013-3320 When configuring CIFS (Configuration > Protocols > CIFS > Configuration >=20 Setup), JavaScript can be inserted into the parameters <domain-name> and=20 <value>. Request (domain-name): POST /zapiServlet HTTP/1.1 Host: 127.0.0.1:1195 [...] <netapp version=3D"1.7" xmlns=3D"http://www.netapp.com/filer/admin"><ci= fs-setup><auth-type>workgroup</auth-type><domain-name><img src=3Dx onerror= =3Dalert(1) ></domain-name><security-style>multiprotocol</security-style><s= erver-name>FILER</server-name></cifs-setup></netapp> Furthermore, when creating new LUNs or editing already existing ones (Stora= ge > LUNs > (Create or Edit)), JavaScript can be inserted into the parameter <comment>. 2) Multiple permanent cross-site scripting vulnerabilities (internal bug=20 number 654355) - CVE-2013-3320 When creating new users or editing already existing ones (Configuration >=20 Local Users and Groups > Users > (Create or Edit)), JavaScript can be inser= ted=20 into the parameters <full-name> and <comment>. Request (full-name): POST /zapiServlet HTTP/1.1 Host: 127.0.0.1:1457 [...] <netapp version=3D"1.7" xmlns=3D"http://www.netapp.com/filer/admin"><us= eradmin-user-modify><useradmin-user><useradmin-user-info><full-name>test<im= g src=3Dx onerror=3Dalert(1) ></full-name><comment>test</comment><name>test= </name><password-maximum-age>4294967295</password-maximum-age><password-min= imum-age>0</password-minimum-age><useradmin-groups><useradmin-group-info><n= ame>Administrators</name></useradmin-group-info></useradmin-groups></userad= min-user-info></useradmin-user></useradmin-user-modify></netapp> Furthermore, when creating new groups or editing already existing ones (Con= figuration >=20 Local Users and Groups > Groups > (Create or Edit)), JavaScript can be=20 inserted into the parameter <comment>. When creating new shares or editing already existing ones (Storage > Shares= > (Create or Edit)), JavaScript can be inserted into the parameter <comment>. 3) Local File Inclusion (internal bug number 654357) - CVE-2013-3321 * When retrieving log files through SnapMirror (Diagnostics > SnapMirror Log)= ,=20 the path can be changed to read arbitrary files from the file system. 4) OS Command Execution (internal bug number 654360) - CVE-2013-3322 * When using the Halt/Reboot interface (Configuration > System Tools > Halt/R= eboot),=20 arbitrary OS commands can be injected. * To exploit these issues, the attacker must be authenticated as root. The= =20 vendor will not fix these issues, as it is considered a design feature. Hen= ce=20 no proof of concept will be included within this advisory. Vendor contact timeline: ------------------------ 2012-11-06: Contacting vendor through security-input@netapp.com 2012-11-06: Initial vendor response 2012-11-07: Forwarding security advisory to vendor 2012-11-07: Vendor acknowledges that the advisory was received 2012-11-14: Asking vendor for a status update 2012-11-14: Vendor asks for more time to address the issues 2012-11-27: Asking vendor for a conference call to discuss further details 2012-11-28: Conference call scheduled for 12th of December 2012-12-12: Conference call=20 2012-12-17: Requested feedback from the vendor 2013-02-07: Requested again for feedback/status update on reported vulnerabilities 2013-03-01: Requested again for feedback/status update on reported=20 vulnerabilities (Received automatic reply (OOTO)) 2013-03-11: Contacted vendor once again, containing publication date of=20 security advisory (2013-04-11) since no response was received s= ince conference call 2013-04-08: Meeting with vendor 2013-04-24: Contacting vendor again with updated advisory 2013-04-25: Vendor replies 2013-05-01: Vendor notified us that version 2.2 was released on 24th April 2013-05-07: Coordinated public release of security advisory Solution: --------- Update to NetApp OnCommand System Manager 2.2 which fixes the stored and=20 reflective cross-site scripting vulnerabilities. Be aware, that OS command execution and file inclusion vulnerabilities are = not fixed and may be exploited by authenticated attackers. Advisory URL: ------------- https://www.sec-consult.com/en/Vulnerability-Lab/Advisories.htm ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ SEC Consult Unternehmensberatung GmbH Office Vienna Mooslackengasse 17 A-1190 Vienna Austria Tel.: +43 / 1 / 890 30 43 - 0 Fax.: +43 / 1 / 890 30 43 - 25 Mail: research at sec-consult dot com Web: https://www.sec-consult.com Blog: http://blog.sec-consult.com Twitter: https://twitter.com/sec_consult EOF M. Heinzl / @2013