Multiple exposures in Sophos UTM
Tim Schughart <[email protected]> Fri, 30 Sep 2016 11:33:31 +0200 (CEST)
| Newsgroups | gmane.comp.security.bugtraq,gmane.comp.security.fulldisclosure,gmane.comp.security.web-applications |
|---|---|
| Message-ID | <477014167.209443.1475228011651.JavaMail.zimbra@prosec-networks.com> |
Hello @all,=20 together with my colleague we found two uncritical vulnerabilities you'll f= ind below. Product: Sophos UTM Vendor: Sophos ltd.=20 Internal reference: ? (Bug ID) Vulnerability type: Information Disclosure Vulnerable version: 9.405-5, 9.404-5 and possible other versions affected (= not tested) Vulnerable component: Frontend Report confidence: yes Solution status: Not fixed by Vendor, no further responses from vendor.=20 Fixed versions: - Researcher credits: Tim Schughart & Khanh Quoc Pham of ProSec Networks Vendor notification: 2016-09-01 Solution date: -=20 Public disclosure: 2016-09-30 CVE reference: CVE-2016-7397 CVSSv3: 6.7 AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N Report timeline: 2016-09-01: Contacted Vendor, vendor acknowledged, no further response=20 2016-09-12: Contacted Vendor again, started to fix=20 2016-09-30: Contacted Vendor again, because there has been no response to o= ur request and our initial told disclosing date, no response again.=20 2016-09-30: Public Disclosure.=20 Vulnerability Details: The password is reflected to DOM and is readable through the "value" field = of the SMTP user settings in notifications tab. You have to be authenticate= d to access the configuration tab.=20 Risk: An attacker gets access to the configured mailbox. Because of Sophos UTM is= a multi user system, this is a problem in bigger company environments with= splitted admin rights. The surface scope is changed, because in bigger env= ironments you are getting access to the configured mailbox, which results i= n an integrity loss.=20 Steps to reproduce: See vulnerability details. -- Product: Sophos UTM Vendor: Sophos ltd.=20 Internal reference: ? (Bug ID) Vulnerability type: Information Disclosure Vulnerable version: 9.405-5, 9.404-5 and possible other versions affected (= not tested) Vulnerable component: Frontend Report confidence: ? Solution status: Not fixed by Vendor Fixed versions: - Researcher credits: Tim Schughart & Khanh Quoc Pham of ProSec Networks Vendor notification: 2016-09-01 Solution date: - Public disclosure: 2016-10-01 CVE reference: CVE-2016-7442=20 CVSSv3: 6.7 AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N Vulnerability Details: The password is reflected to DOM and is readable through the "value" field = of the proxy user settings in the system settings / scan settings / anti sp= am. You have to be authenticated to access the configuration tab. Risk: An attacker gets access to the configured proxy user. Because of Sophos UTM= is a multi user system, this is a problem in bigger company environments w= ith splitted admin rights. The surface scope is changed, because in bigger = environments you are getting access to the configured proxy user, which res= ults in an privilege escalation.=20 Steps to reproduce: See vulnerability details.=20 Best regards / Mit freundlichen Gr=C3=BC=C3=9Fen=20 Tim Schughart=20 CEO / Gesch=C3=A4ftsf=C3=BChrer =20 -- ProSec Networks e.K.=20 Ellingshohl 82 =20 56077 Koblenz=20 Website: https://www.prosec-networks.com=20 E-Mail: [email protected]=20 Mobile: +49 (0)157 7901 5826 Phone: +49 (0)261 450 930 90 =20 "This E-Mail communication may contain CONFIDENTIAL, PRIVILEGED and/or LEGA= LLY PROTECTED information and is intended only for the named recipient(s). = Any unauthorized use, dissemination, copying or forwarding is strictly proh= ibited. If you are not the intended recipient and have received this email = communication in error, please notify the sender immediately, delete it and= destroy all copies of this E-Mail. VAT ID: DE290654714 legal domicile Kobl= enz, HRA 21625.=E2=80=9C "Diese E-Mail Mitteilung kann VERTRAULICHE, dem BERUFSGEHEIMNIS UNTERLIEGEN= DE und/oder RECHTLICH GESCH=C3=9CTZTE Informationen enthalten und ist aussc= hlie=C3=9Flich f=C3=BCr den/die genannten Adressaten bestimmt. Jede unbefug= te Nutzung, Weitergabe, Vervielf=C3=A4ltigung oder Versendung ist strengste= ns verboten. Sollten Sie nicht der angegebene Adressat sein und diese E-Mai= l Mitteilung irrt=C3=BCmlich erhalten haben, informieren Sie bitte sofort d= en Absender, l=C3=B6schen diese E-Mail und vernichten alle Kopien. USt-IdNr= .: DE290654714, Amtsgericht Koblenz, HRA 21625."