Nortel Contivity Denial of Service and File Viewing Vulnerabilities

BID:938

Info

Nortel Contivity Denial of Service and File Viewing Vulnerabilities

Bugtraq ID: 938
Class: Failure to Handle Exceptional Conditions
CVE:
Remote: Yes
Local: No
Published: Jan 18 2000 12:00AM
Updated: Jan 18 2000 12:00AM
Credit: First posted to Bugtraq by foo <[email protected]> on January 18, 2000.
Vulnerable: Nortel Networks Contivity Extranet Switch 2500
Not Vulnerable:

Discussion

Nortel Contivity Denial of Service and File Viewing Vulnerabilities

Nortel's recently released Contivity series network devices (extranet switches) shipped with an httpd (to provide an interface for remote administration) which runs on top of VxWorks. A total system crash can occur as a result of exploiting a vulnerability in a cgi-bin program called "cgiproc" that is included with the webserver. If metacharacters such as "!", or "$" are passed to cgiproc, the system will crash (because the characters are not escaped).

foo <[email protected]> provided the following example:

http://x.x.x.x/manage/cgi/cgiproc?$

[crash]

No evidence of this problem being exploited is saved in the logs.

Another vulnerability in cgiproc is a lack of authentication when requesting administration webpages. A consequence of this is an attacker being able to view any file on the webserver.

foo <[email protected]> also provided an example for this vulnerability:

http://x.x.x.x/manage/cgi/cgiproc?Nocfile=/name/and/path/of/file.

(interesting places to look: /system/filelist.dat, /system/version.dat, /system/keys, /system/core, etc.)

All that is written to the logs when this is exploited is below:

09:44:23 tEvtLgMgr 0 : Security [12] Management: Request for cgiproc denied. requires login

In order to perform the operations detailed in the report, the "attackers" must be internal, private side users or authenticated tunnel users and the site administrator must allow them HTTP as a management protocol.

Exploit / POC

Nortel Contivity Denial of Service and File Viewing Vulnerabilities

See discussion.

Solution / Fix

Nortel Contivity Denial of Service and File Viewing Vulnerabilities

Solution:
Nortel has opened cases for each of these vulnerabilities:

CR# 118890 - DoS

CR# 118887 - cgiproc 'bug'

A fix is planned for the next release of VxWorks (V2.60).

References

Nortel Contivity Denial of Service and File Viewing Vulnerabilities

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report