vendor:
SteelHead VCX
by:
Gregory DRAPERI
7,5
CVSS
HIGH
Arbitry file reading
22
CWE
Product Name: SteelHead VCX
Affected Version From: SteelHead VCX (VCX255U) (x86_64) 9.6.0a
Affected Version To: SteelHead VCX (VCX255U) (x86_64) 9.6.0a
Patch Exists: YES
Related CWE: N/A
CPE: a:riverbed:steelhead_vcx
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2017
Arbitry file reading by authenticated users on Riverbed SteelHead VCX
An authenticated user can read arbitrary files on Riverbed SteelHead VCX. This exploit was discovered by Gregory DRAPERI in 2017. The vulnerable version is SteelHead VCX (VCX255U) (x86_64) 9.6.0a. The exploit uses a Session object to authenticate the user and then uses a GET request to read the arbitrary file.
Mitigation:
Ensure that the authentication process is secure and that the user is not able to access any arbitrary file.