vendor:
Network Automation
by:
Nate Kettlewell
7,5
CVSS
HIGH
OS Command Injection
78
CWE
Product Name: Network Automation
Affected Version From: 6.4.X.X
Affected Version To: 6.8.4.X
Patch Exists: YES
Related CWE: CVE-2014-3418
CPE: 2.3:a:infoblox:network_automation
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2014
OS Command Injection in Infoblox Network Automation Products
Depth Security discovered a vulnerability in the Infoblox Network Automation management web interface. This attack does not require authentication of any kind. The vulnerability exists due to insufficient sanitization of user-supplied data in in skipjackUsername POST parameter. A remote attacker can inject operating system commands as the root user, and completely compromise the operating system.
Mitigation:
Infoblox immediately released a hotfix to remediate this vulnerability on existing installations (v6.X-NETMRI-20710.gpg). The flaw was corrected in the 6.8.5 release (created expressly for dealing with this issue), and that release has been put into manufacturing for new appliances.