PT-2016-3222 · Dnalims · Dnalims

H00Die

+2

·

Published

2016-11-06

·

Updated

2019-10-03

·

CVE-2017-6526

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions dnaLIMS version 4-2015s13
Description The issue concerns an improperly protected administrative web shell, allowing unauthenticated command execution. This can be exploited through cgi-bin/dna/sysAdmin.cgi using specially crafted POST requests, enabling a remote attacker to execute arbitrary commands. The vulnerability is related to the lack of input data sanitization measures in the administrative web shell of the dnaLIMS software.
Recommendations For dnaLIMS version 4-2015s13, consider disabling access to the cgi-bin/dna/sysAdmin.cgi endpoint until a patch is available to prevent exploitation. Restricting access to this administrative web shell can help minimize the risk of command execution. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Command Injection

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2017-02590
CVE-2017-6526

Affected Products

Dnalims