Fujitsu Systemcast Wizard Lite TFTP Directory Traversal Vulnerability
BID:33344
Info
Fujitsu Systemcast Wizard Lite TFTP Directory Traversal Vulnerability
| Bugtraq ID: | 33344 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 19 2009 12:00AM |
| Updated: | Jan 21 2009 10:12PM |
| Credit: | This issue was disclosed by the vendor. |
| Vulnerable: |
Fujitsu Systemcast Wizard Lite 2.0a Fujitsu Systemcast Wizard Lite 2.0 Fujitsu Systemcast Wizard Lite 1.9 Fujitsu Systemcast Wizard Lite 1.8a Fujitsu Systemcast Wizard Lite 1.8 Fujitsu Systemcast Wizard Lite 1.7 |
| Not Vulnerable: | |
Discussion
Fujitsu Systemcast Wizard Lite TFTP Directory Traversal Vulnerability
Fujitsu Systemcast Wizard Lite is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input.
Exploiting this issue can allow an attacker to access arbitrary files outside of the TFTP server root directory. This can expose sensitive information that could help the attacker launch further attacks.
Systemcast Wizard Lite 2.0A and prior are vulnerable.
Fujitsu Systemcast Wizard Lite is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input.
Exploiting this issue can allow an attacker to access arbitrary files outside of the TFTP server root directory. This can expose sensitive information that could help the attacker launch further attacks.
Systemcast Wizard Lite 2.0A and prior are vulnerable.
Exploit / POC
Fujitsu Systemcast Wizard Lite TFTP Directory Traversal Vulnerability
Attackers can use readily available tools to exploit this issue.
Attackers can use readily available tools to exploit this issue.
Solution / Fix
Fujitsu Systemcast Wizard Lite TFTP Directory Traversal Vulnerability
Solution:
Vendor patches are available; please see the references for more information.
Fujitsu Systemcast Wizard Lite 1.8a
Fujitsu Systemcast Wizard Lite 1.7
Fujitsu Systemcast Wizard Lite 2.0a
Fujitsu Systemcast Wizard Lite 1.8
Fujitsu Systemcast Wizard Lite 1.9
Fujitsu Systemcast Wizard Lite 2.0
Solution:
Vendor patches are available; please see the references for more information.
Fujitsu Systemcast Wizard Lite 1.8a
-
Fujitsu TKH0139.exe
http://www.fujitsu.com/downloads/PRMQST/documents/TKH0139.exe
Fujitsu Systemcast Wizard Lite 1.7
-
Fujitsu TKF0139.exe
http://www.fujitsu.com/downloads/PRMQST/documents/TKF0139.exe
Fujitsu Systemcast Wizard Lite 2.0a
-
Fujitsu TKL0139.exe
http://www.fujitsu.com/downloads/PRMQST/documents/TKL0139.exe
Fujitsu Systemcast Wizard Lite 1.8
-
Fujitsu TKG0139.exe
http://www.fujitsu.com/downloads/PRMQST/documents/TKG0139.exe
Fujitsu Systemcast Wizard Lite 1.9
-
Fujitsu TKJ0139.exe
http://www.fujitsu.com/downloads/PRMQST/documents/TKJ0139.exe
Fujitsu Systemcast Wizard Lite 2.0
-
Fujitsu TKK0139.exe
http://www.fujitsu.com/downloads/PRMQST/documents/TKK0139.exe
References
Fujitsu Systemcast Wizard Lite TFTP Directory Traversal Vulnerability
References:
References:
- Fujitsu Homepage (Fujitsu)
- Precautions when using Windows Server 2008 (Fujitsu)
- Systemcast Wizard Lite Patch (Fujitsu)