Cisco IDS Device Manager Arbitrary File Read Access Vulnerability
BID:4760
Info
Cisco IDS Device Manager Arbitrary File Read Access Vulnerability
| Bugtraq ID: | 4760 |
| Class: | Input Validation Error |
| CVE: |
CVE-2002-0908 |
| Remote: | Yes |
| Local: | No |
| Published: | May 17 2002 12:00AM |
| Updated: | Jul 11 2009 12:46PM |
| Credit: | Discovered by Andrew Lopacki <[email protected]>. |
| Vulnerable: |
Cisco IDS Device Manager 3.1.1 |
| Not Vulnerable: | |
Discussion
Cisco IDS Device Manager Arbitrary File Read Access Vulnerability
IDS Device Manager is a web interface to the Cisco IDS systems. It is distributed and maintained by Cisco Systems.
The IDS Device Manager may allow a remote user to gain access to sensitive information on the system. Due to improper handling of user-supplied input, it is possible for a user to gain access to arbitrary files on the system using an elementary directory traversal attack. By placing a request to the process, with an appended dot-dot-slash (../) tag pointing to a file, a remote user may read the specified file on the affected system.
IDS Device Manager is a web interface to the Cisco IDS systems. It is distributed and maintained by Cisco Systems.
The IDS Device Manager may allow a remote user to gain access to sensitive information on the system. Due to improper handling of user-supplied input, it is possible for a user to gain access to arbitrary files on the system using an elementary directory traversal attack. By placing a request to the process, with an appended dot-dot-slash (../) tag pointing to a file, a remote user may read the specified file on the affected system.
Exploit / POC
Cisco IDS Device Manager Arbitrary File Read Access Vulnerability
This vulnerability may be exploited with a web browser. The following example has been provided:
https://example.com/../../../../../etc/shadow
This vulnerability may be exploited with a web browser. The following example has been provided:
https://example.com/../../../../../etc/shadow
Solution / Fix
Cisco IDS Device Manager Arbitrary File Read Access Vulnerability
Solution:
Reports indicate a fixed version number 3.1.2 will be available through Cisco TAC on May 18, 2002.
Solution:
Reports indicate a fixed version number 3.1.2 will be available through Cisco TAC on May 18, 2002.
References
Cisco IDS Device Manager Arbitrary File Read Access Vulnerability
References:
References: