APC Network Management Card Cross Site Request Forgery and Cross Site Scripting Vulnerabilities
BID:37338
Info
APC Network Management Card Cross Site Request Forgery and Cross Site Scripting Vulnerabilities
| Bugtraq ID: | 37338 |
| Class: | Input Validation Error |
| CVE: |
CVE-2009-1797 CVE-2009-1798 CVE-2009-4406 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 15 2009 12:00AM |
| Updated: | Feb 25 2010 05:41PM |
| Credit: | Jamal Pecou, Russ McRee |
| Vulnerable: |
APC Switched Rack PDU AP7932 APC Network Management Card 0 |
| Not Vulnerable: |
APC Network Management Card 5.1.1 APC Network Management Card 3.7.2 |
Discussion
APC Network Management Card Cross Site Request Forgery and Cross Site Scripting Vulnerabilities
The APC Network Management Card is prone to multiple cross-site request-forgery and cross-site scripting vulnerabilities.
An attacker can exploit the cross-site request forgery issues to alter the settings on affected devices, which may lead to further network-based attacks.
The attacker can exploit the cross-site scripting issues to execute arbitrary script code in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials. Other attacks are also possible.
Versions prior to the following are vulnerable:
Network Management Card Firmware 3.7.2
Network Management Card Firmware 5.1.1
The APC Network Management Card is prone to multiple cross-site request-forgery and cross-site scripting vulnerabilities.
An attacker can exploit the cross-site request forgery issues to alter the settings on affected devices, which may lead to further network-based attacks.
The attacker can exploit the cross-site scripting issues to execute arbitrary script code in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials. Other attacks are also possible.
Versions prior to the following are vulnerable:
Network Management Card Firmware 3.7.2
Network Management Card Firmware 5.1.1
Exploit / POC
APC Network Management Card Cross Site Request Forgery and Cross Site Scripting Vulnerabilities
To exploit these issues, an attacker must entice an unsuspecting victim into following a malicious URI.
The following example is available:
To exploit these issues, an attacker must entice an unsuspecting victim into following a malicious URI.
The following example is available:
Solution / Fix
APC Network Management Card Cross Site Request Forgery and Cross Site Scripting Vulnerabilities
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.
References
APC Network Management Card Cross Site Request Forgery and Cross Site Scripting Vulnerabilities
References:
References: