PT-2015-3286 · Samsung · Samsung Syncthru 6

Andrea Micalizzi

+1

·

Published

2015-05-18

·

Updated

2017-06-12

·

CVE-2015-5473

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Samsung SyncThru 6 versions prior to 1.0
Description The vulnerability exists in the Samsung SyncThru 6 web application due to incorrect restriction of the directory path name with limited access. Exploitation of the vulnerability may allow a remote attacker to execute arbitrary code with SYSTEM privileges using a specially crafted GET request with parameters such as uploadCloning.html, fileupload.html, uploadFirmware.html, or upload/driver. The vulnerability also allows a remote attacker to delete arbitrary files via unspecified parameters to upload/updateDriver or upload/addDriver.
Recommendations For Samsung SyncThru 6 versions prior to 1.0, update to version 1.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable servlets, such as DriverFileUploadServlet, FileUploadController, and AddDriverFileServlet, until a patch is available. Avoid using the parameters uploadCloning.html, fileupload.html, uploadFirmware.html, or upload/driver in the affected API endpoints until the issue is resolved.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2017-01852
BDU:2017-01853
BDU:2017-01854
BDU:2017-01855
BDU:2017-01856
BDU:2017-01857
CVE-2015-5473
ZDI-15-296
ZDI-15-297
ZDI-15-298
ZDI-15-299
ZDI-15-300
ZDI-15-301

Affected Products

Samsung Syncthru 6