vendor:
XG Firewall
by:
An independent security researcher
N/A
CVSS
N/A
Path Traversal and Missing Function Level Access Control
22
CWE
Product Name: XG Firewall
Affected Version From: 16.05.4 MR-4
Affected Version To: 16.05.4 MR-4
Patch Exists: Yes
Related CWE: CVE-2017-12854
CPE: a:sophos:xg_firewall
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2017
Vulnerabilities Summary
Crafting the download request and adding a path traversal vector to it, an authenticated user, can use this function to download files that are outside the normal scope of the download feature (including sensitive files). In addition, the function can be called from a low privileged user, a user that is logged on to the User Portal (i.e. Missing Function Level Access Control), a combinations of these two vulnerabilities can be used to compromise the integrity of the server, by allowing a User Portal to elevate his privileges.
Mitigation:
The vendor has released patches to address this vulnerability: “The patches were released as part of SFOS 16.05.5 MR5: https://community.sophos.com/products/xg-firewall/b/xg-blog/posts/sfos-16-05-5-mr5-released Our internal bug number was NC-18958, mentioned in the changelog”