SolarWinds Orion Platform... CVE-2020-27871

9.0 AV AC AU C I A
发布: 2021-02-10
修订: 2024-11-21

**CVE-2020-27871: Directory Traversal leading to arbitrary file upload** Orion allows the installation of various modules, with each module capable of performing a specific network monitoring and management function. One such module is the Network Configuration Manager (NCM) module. Where this module is installed, there is an arbitrary file upload vulnerability that could be leveraged for remote code execution. The root cause of this vulnerability is illustrated in the following code snippet: As shown, the NCM module has a firmware vulnerability management functionality that downloads a ZIP file containing JSON files from an external website. By default, it downloads from `https://nvd.nist.gov`, but this default can be overridden. It then automatically extracts data from the .zip archive. It does not check the file extensions of the extracted files, nor does it verify the file upload path. Thus it is possible to upload the file anywhere in the file system. Files are extracted and...

0%
暂无可用Exp或PoC
当前有1条受影响产品信息