Multiple exposures in Sophos UTM

Tim Schughart <[email protected]> Fri, 30 Sep 2016 11:33:31 +0200 (CEST)
Newsgroups gmane.comp.security.bugtraq,gmane.comp.security.fulldisclosure,gmane.comp.security.web-applications
Message-ID <477014167.209443.1475228011651.JavaMail.zimbra@prosec-networks.com>
Hello @all,=20

together with my colleague we found two uncritical vulnerabilities you'll f=
ind below.

Product: Sophos UTM
Vendor: Sophos ltd.=20

Internal reference: ? (Bug ID)
Vulnerability type: Information Disclosure
Vulnerable version: 9.405-5, 9.404-5 and possible other versions affected (=
not tested)
Vulnerable component: Frontend
Report confidence: yes
Solution status: Not fixed by Vendor, no further responses from vendor.=20
Fixed versions: -
Researcher credits: Tim Schughart & Khanh Quoc Pham of ProSec Networks
Vendor notification: 2016-09-01
Solution date: -=20
Public disclosure: 2016-09-30
CVE reference: CVE-2016-7397
CVSSv3: 6.7 AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N

Report timeline:
2016-09-01: Contacted Vendor, vendor acknowledged, no further response=20
2016-09-12: Contacted Vendor again, started to fix=20
2016-09-30: Contacted Vendor again, because there has been no response to o=
ur request and our initial told disclosing date, no response again.=20
2016-09-30: Public Disclosure.=20

Vulnerability Details:
The password is reflected to DOM and is readable through the "value" field =
of the SMTP user settings in notifications tab. You have to be authenticate=
d to access the configuration tab.=20

Risk:
An attacker gets access to the configured mailbox. Because of Sophos UTM is=
 a multi user system, this is a problem in bigger company environments with=
 splitted admin rights. The surface scope is changed, because in bigger env=
ironments you are getting access to the configured mailbox, which results i=
n an integrity loss.=20

Steps to reproduce:
See vulnerability details.


--


Product: Sophos UTM
Vendor: Sophos ltd.=20

Internal reference: ? (Bug ID)
Vulnerability type: Information Disclosure
Vulnerable version: 9.405-5, 9.404-5 and possible other versions affected (=
not tested)
Vulnerable component: Frontend
Report confidence: ?
Solution status: Not fixed by Vendor
Fixed versions: -
Researcher credits: Tim Schughart & Khanh Quoc Pham of ProSec Networks
Vendor notification: 2016-09-01
Solution date: -
Public disclosure: 2016-10-01
CVE reference: CVE-2016-7442=20
CVSSv3: 6.7 AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N

Vulnerability Details:
The password is reflected to DOM and is readable through the "value" field =
of the proxy user settings in the system settings / scan settings / anti sp=
am. You have to be authenticated to access the configuration tab.

Risk:
An attacker gets access to the configured proxy user. Because of Sophos UTM=
 is a multi user system, this is a problem in bigger company environments w=
ith splitted admin rights. The surface scope is changed, because in bigger =
environments you are getting access to the configured proxy user, which res=
ults in an privilege escalation.=20

Steps to reproduce:
See vulnerability details.=20


Best regards / Mit freundlichen Gr=C3=BC=C3=9Fen=20

Tim Schughart=20
CEO / Gesch=C3=A4ftsf=C3=BChrer =20

--
ProSec Networks e.K.=20
Ellingshohl 82 =20
56077 Koblenz=20

Website: https://www.prosec-networks.com=20
E-Mail: [email protected]=20
Mobile: +49 (0)157 7901 5826
Phone: +49 (0)261 450 930 90  =20

"This E-Mail communication may contain CONFIDENTIAL, PRIVILEGED and/or LEGA=
LLY PROTECTED information and is intended only for the named recipient(s). =
Any unauthorized use, dissemination, copying or forwarding is strictly proh=
ibited. If you are not the intended recipient and have received this email =
communication in error, please notify the sender immediately, delete it and=
 destroy all copies of this E-Mail. VAT ID: DE290654714 legal domicile Kobl=
enz, HRA 21625.=E2=80=9C

"Diese E-Mail Mitteilung kann VERTRAULICHE, dem BERUFSGEHEIMNIS UNTERLIEGEN=
DE und/oder RECHTLICH GESCH=C3=9CTZTE Informationen enthalten und ist aussc=
hlie=C3=9Flich f=C3=BCr den/die genannten Adressaten bestimmt. Jede unbefug=
te Nutzung, Weitergabe, Vervielf=C3=A4ltigung oder Versendung ist strengste=
ns verboten. Sollten Sie nicht der angegebene Adressat sein und diese E-Mai=
l Mitteilung irrt=C3=BCmlich erhalten haben, informieren Sie bitte sofort d=
en Absender, l=C3=B6schen diese E-Mail und vernichten alle Kopien. USt-IdNr=
.:  DE290654714, Amtsgericht Koblenz, HRA 21625."