PT-2013-6122 · Emc+1 · Emc Connectrix Manager Converged Network Edition+1

James Fitts

·

Published

2013-12-12

·

Updated

2017-09-16

·

CVE-2013-6810

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Brocade Network Advisor versions prior to 12.1.0
Description The issue allows remote attackers to execute arbitrary code by using a servlet to upload an executable file. This is related to the FileUploadController Servlet in EMC Connectrix Manager Converged Network Edition.
Recommendations For versions prior to 12.1.0, update to version 12.1.0 or later to resolve the issue. As a temporary workaround, consider disabling the servlet functionality to minimize the risk of exploitation. Restrict access to the vulnerable servlets, such as UnifiedFileUploadMoreInfoServlet, BootFileUploadMoreInfoServlet, and SoftwareFileUploadMoreInfoServlet, to prevent remote code execution.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-6810
ZDI-13-278
ZDI-13-279
ZDI-13-280
ZDI-13-281
ZDI-13-282
ZDI-13-283

Affected Products

Brocade Network Advisor
Emc Connectrix Manager Converged Network Edition