2024-12-08 03:06:42 +00:00

124 lines
4.3 KiB
JSON

{
"id": "CVE-2018-1162",
"sourceIdentifier": "zdi-disclosures@trendmicro.com",
"published": "2018-02-08T18:29:01.353",
"lastModified": "2024-11-21T03:59:18.770",
"vulnStatus": "Modified",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "This vulnerability allows remote attackers to create a denial-of-service condition on vulnerable installations of Quest NetVault Backup 11.2.0.13. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be easily bypassed. The specific flaw exists within the handling of Export requests. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to arbitrarily overwrite files resulting in a denial-of-service condition. Was ZDI-CAN-4222."
},
{
"lang": "es",
"value": "Esta vulnerabilidad permite que los atacantes remotos creen una condici\u00f3n de denegaci\u00f3n de servicio (DoS) en instalaciones vulnerables de Quest NetVault Backup 11.2.0.13. Aunque se requiere autenticaci\u00f3n para explotar esta vulnerabilidad, el mecanismo de autenticaci\u00f3n existente se puede omitir f\u00e1cilmente. Este error en concreto existe en la gesti\u00f3n de peticiones Export. El problema deriva de la falta de validaci\u00f3n correcta de una ruta proporcionada por el usuario antes de emplearla en operaciones de archivo. Un atacante puede aprovechar la vulnerabilidad para sobrescribir archivos arbitrariamente, lo que resulta en una condici\u00f3n de denegaci\u00f3n de servicio (DoS). Anteriormente era ZDI-CAN-4222."
}
],
"metrics": {
"cvssMetricV30": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.0",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H",
"baseScore": 8.1,
"baseSeverity": "HIGH",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "LOW",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "NONE",
"integrityImpact": "HIGH",
"availabilityImpact": "HIGH"
},
"exploitabilityScore": 2.8,
"impactScore": 5.2
}
],
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:S/C:N/I:C/A:C",
"baseScore": 8.5,
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "SINGLE",
"confidentialityImpact": "NONE",
"integrityImpact": "COMPLETE",
"availabilityImpact": "COMPLETE"
},
"baseSeverity": "HIGH",
"exploitabilityScore": 8.0,
"impactScore": 9.2,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "zdi-disclosures@trendmicro.com",
"type": "Secondary",
"description": [
{
"lang": "en",
"value": "CWE-22"
}
]
},
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "NVD-CWE-noinfo"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:quest:netvault_backup:11.2.0.13:*:*:*:*:*:*:*",
"matchCriteriaId": "E6C12817-69AE-4931-B9F2-E36693F7980C"
}
]
}
]
}
],
"references": [
{
"url": "https://zerodayinitiative.com/advisories/ZDI-18-005",
"source": "zdi-disclosures@trendmicro.com",
"tags": [
"Third Party Advisory",
"VDB Entry"
]
},
{
"url": "https://zerodayinitiative.com/advisories/ZDI-18-005",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Third Party Advisory",
"VDB Entry"
]
}
]
}