ID

VAR-201710-1448


TITLE

There are two arbitrary file upload vulnerabilities in the bunker fortress background

Trust: 0.6

sources: CNVD: CNVD-2017-25413

DESCRIPTION

The bunker bastion machine is the industry's first software bastion machine, which provides single point functions of centralized identity authentication, centralized access authorization, centralized access management, centralized operation audit, and simplified operation and management required for remote operation and maintenance management. There are two arbitrary file upload vulnerabilities in the background system settings "Workflow Settings" and "System Upgrade Function" of the Bunker Fortress Machine, allowing attackers to upload a webshell and gain server permissions.

Trust: 0.6

sources: CNVD: CNVD-2017-25413

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2017-25413

AFFECTED PRODUCTS

vendor:weifangtong informationmodel:bunker fortressscope:eqversion:v2.26

Trust: 0.6

sources: CNVD: CNVD-2017-25413

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2017-25413
value: HIGH

Trust: 0.6

CNVD: CNVD-2017-25413
severity: HIGH
baseScore: 9.0
vectorString: AV:N/AC:L/AU:S/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 8.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2017-25413

PATCH

title:Bunker Fortress CMS Has Arbitrary File Upload Vulnerabilityurl:https://www.cnvd.org.cn/patchinfo/show/100784

Trust: 0.6

sources: CNVD: CNVD-2017-25413

EXTERNAL IDS

db:CNVDid:CNVD-2017-25413

Trust: 0.6

sources: CNVD: CNVD-2017-25413

SOURCES

db:CNVDid:CNVD-2017-25413

LAST UPDATE DATE

2022-05-04T10:16:09.231000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2017-25413date:2017-09-28T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2017-25413date:2017-10-09T00:00:00