PT-2017-3498 · Trustwave · Trustwave Secure Web Gateway

Maor Shwartz

·

Publicado

2017-12-26

·

Atualizado

2019-10-03

·

CVE-2017-18001

CVSS v3.1

10

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Trustwave Secure Web Gateway (SWG) versions prior to 11.8.0.28
Description The issue is related to errors in cryptographic key management. It allows remote attackers to append an arbitrary public key to the device's SSH Authorized Keys data, and consequently obtain remote root access. This can be achieved via the publicKey parameter to the "/sendKey" URI.
Recommendations For Trustwave Secure Web Gateway (SWG) versions prior to 11.8.0.28, update to version 11.8.0.28 or later to resolve the issue. As a temporary workaround, consider restricting access to the /sendKey URI to minimize the risk of exploitation. Avoid using the publicKey parameter in the affected HTTP POST request until the issue is resolved.

Exploit

Correção

Missing Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2018-00326
CVE-2017-18001

Produtos afetados

Trustwave Secure Web Gateway