vendor:
Clusterwatch/Watchware
by:
Anonymous
8,8
CVSS
HIGH
Authentication Bypass, Remote Code Execution, File Write
287, 78, 264
CWE
Product Name: Clusterwatch/Watchware
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: AIX
Before 2020
Bull Clusterwatch/Watchware Vulnerabilities
Bull Clusterwatch/Watchware is a web application with CGIs (shell scripts and binaries) that is vulnerable to authentication bypass, remote code execution, and file write. An attacker can exploit these vulnerabilities to fully compromise servers running Watchware. The authentication bypass vulnerability is trivial, as the credentials are smwadmin/bullsmw. The file write vulnerability is exploitable by sending a request to write a shellcode to the system file. The remote code execution vulnerability is exploitable by sending a request to inject OS commands in the “lpp” field.
Mitigation:
Ensure that the Bull Clusterwatch/Watchware application is up to date and patched with the latest security updates.