PT-2017-3511 · Quest · Quest Netvault Backup

Rgod

·

Publicado

2017-12-06

·

Atualizado

2019-10-09

·

CVE-2018-1163

CVSS v3.1

10

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Quest NetVault Backup version 11.2.0.13
Description This issue allows remote attackers to bypass authentication on vulnerable installations. The flaw exists within JSON RPC Request handling, specifically by setting the checksession parameter to a certain value, enabling bypass of authentication to critical functions. An attacker can leverage this, potentially in conjunction with other issues, to execute arbitrary code in the context of SYSTEM. The vulnerability is related to incorrect access control.
Recommendations For Quest NetVault Backup version 11.2.0.13, as a temporary workaround, consider restricting access to the JSON RPC Request handling functionality or specifically the checksession parameter until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2018-00362
CVE-2018-1163
ZDI-18-006

Produtos afetados

Quest Netvault Backup