PT-2015-3286 · Samsung · Samsung Syncthru 6

Andrea Micalizzi

+1

·

Publicado

2015-05-18

·

Atualizado

2017-06-12

·

CVE-2015-5473

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Samsung SyncThru 6 versions prior to 1.0
Description The vulnerability exists in the Samsung SyncThru 6 web application due to incorrect restriction of the directory path name with limited access. Exploitation of the vulnerability may allow a remote attacker to execute arbitrary code with SYSTEM privileges using a specially crafted GET request with parameters such as uploadCloning.html, fileupload.html, uploadFirmware.html, or upload/driver. The vulnerability also allows a remote attacker to delete arbitrary files via unspecified parameters to upload/updateDriver or upload/addDriver.
Recommendations For Samsung SyncThru 6 versions prior to 1.0, update to version 1.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable servlets, such as DriverFileUploadServlet, FileUploadController, and AddDriverFileServlet, until a patch is available. Avoid using the parameters uploadCloning.html, fileupload.html, uploadFirmware.html, or upload/driver in the affected API endpoints until the issue is resolved.

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2017-01852
BDU:2017-01853
BDU:2017-01854
BDU:2017-01855
BDU:2017-01856
BDU:2017-01857
CVE-2015-5473
ZDI-15-296
ZDI-15-297
ZDI-15-298
ZDI-15-299
ZDI-15-300
ZDI-15-301

Produtos afetados

Samsung Syncthru 6