vendor:
ERS Data System
by:
West Shepherd
9,8
CVSS
CRITICAL
Deserialize Vulnerability
502
CWE
Product Name: ERS Data System
Affected Version From: 1.8.1.0
Affected Version To: 1.8.1.0
Patch Exists: YES
Related CWE: CVE-2017-14702
CPE: a:ersdata:ers_data_system:1.8.1.0
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 7 x86
2017
ERS Data System 1.8.1 Deserialize Vulnerability
ERS Data System 1.8.1 allows remote attackers to execute arbitrary code, related to the use of com.branaghgroup.ecers.update.UpdateRequest deserialization. To exploit this vulnerability, an attacker can enable packet forwarding and poison DNS requests to the www.ersdata.com domain. Then, the attacker can run a request handler on the attacking machine, which will answer all requests with malicious serialized gadgets.
Mitigation:
Ensure that the ERS Data System thick client is connecting to the www.ersdata.com API via an encrypted connection on TCP port 3311.