ID

VAR-201705-4197


TITLE

Beijing Weifangtong Information Technology Co., Ltd. bunker fortress machine has S2-045 remote command execution vulnerability

Trust: 0.6

sources: CNVD: CNVD-2017-03990

DESCRIPTION

Beijing Weifangtong Information Technology Co., Ltd. bunker fortress is a single point function that provides centralized identity authentication, centralized access authorization, centralized access management, centralized operation audit, and simplified operation and management required for remote operation and maintenance management. Beijing Weifangtong Information Technology Co., Ltd. bunker fortress based on Jakarta Multipart parser's file upload module captures the exception information when processing the file upload (multipart) request, and OGNL expression processing for the exception information. However, when the content-type is judged to be incorrect, an exception is thrown and the Content-Type attribute value is taken. The URL with OGNL expression can be carefully constructed to cause remote code execution.

Trust: 0.6

sources: CNVD: CNVD-2017-03990

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2017-03990

AFFECTED PRODUCTS

vendor:weifangtong informationmodel:bunker fortressscope:eqversion:2.23

Trust: 0.6

sources: CNVD: CNVD-2017-03990

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2017-03990
value: HIGH

Trust: 0.6

CNVD: CNVD-2017-03990
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2017-03990

PATCH

title:Beijing Weifangtong Information Technology Co., Ltd. bunker fortress machine has S2-045 remote command execution vulnerabilityurl:https://www.cnvd.org.cn/patchinfo/show/91343

Trust: 0.6

sources: CNVD: CNVD-2017-03990

EXTERNAL IDS

db:CNVDid:CNVD-2017-03990

Trust: 0.6

sources: CNVD: CNVD-2017-03990

SOURCES

db:CNVDid:CNVD-2017-03990

LAST UPDATE DATE

2022-05-04T09:39:32.369000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2017-03990date:2017-09-28T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2017-03990date:2017-05-16T00:00:00