vendor:
NetFlow Analyzer and IT360
by:
Pedro Ribeiro
N/A
CVSS
N/A
Arbitrary file download
434
CWE
Product Name: NetFlow Analyzer and IT360
Affected Version From: NetFlow v8.6
Affected Version To: NetFlow v10.2, IT360 v10.3 and above
Patch Exists: YES
Related CWE: CVE-2014-5445, CVE-2014-5446
CPE: a:manageengine:netflow_analyzer
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows, Linux
2014
Arbitrary file download in ManageEngine Netflow Analyzer and IT360
This vulnerability allows an unauthenticated attacker to download arbitrary files from the server. It affects NetFlow Analyzer versions 8.6 to 10.2 and IT360 versions 10.3 and above. A Metasploit module has been released to exploit CVE-2014-5445.
Mitigation:
ManageEngine have released a patch for this vulnerability.