// For flags

CVE-2013-6810

EMC Connectrix Manager Converged Network Edition inmservlets.war SoftwareFileUploadMoreInfoServlet Remote Code Execution Vulnerability

Severity Score

10.0
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

2
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The server in Brocade Network Advisor before 12.1.0, as used in EMC Connectrix Manager Converged Network Edition (CMCNE), HP B-series SAN Network Advisor, and possibly other products, allows remote attackers to execute arbitrary code by using a servlet to upload an executable file.

El servidor en EMC Connectrix Manager Converged Network Edition (CMCNE) 11.2.1, 12.0.1, y 12.0.3 permite a atacantes remotos ejecutar código arbitrario mediante el uso de un servlet para subir un archivo ejecutable.

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of EMC Connectrix Manager Converged Network Edition. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the 'SoftwareFileUploadMoreInfoServlet', which allows an unauthenticated user to copy any file to an arbitrary location on the server. When combined with information disclosure vulnerabilities, an attacker can leverage this directory traversal vulnerability into arbitrary code execution on the compromised server in the security context of the Administrator account.

*Credits: Andrea Micalizzi aka rgod
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2013-11-19 CVE Reserved
  • 2013-12-12 CVE Published
  • 2023-06-08 EPSS Updated
  • 2024-08-06 CVE Updated
  • 2024-08-06 First Exploit
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-94: Improper Control of Generation of Code ('Code Injection')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Emc
Search vendor "Emc"
Connectrix Manager
Search vendor "Emc" for product "Connectrix Manager"
11.2.1
Search vendor "Emc" for product "Connectrix Manager" and version "11.2.1"
converged_network_edition
Affected
Emc
Search vendor "Emc"
Connectrix Manager
Search vendor "Emc" for product "Connectrix Manager"
12.0.1
Search vendor "Emc" for product "Connectrix Manager" and version "12.0.1"
converged_network_edition
Affected
Emc
Search vendor "Emc"
Connectrix Manager
Search vendor "Emc" for product "Connectrix Manager"
12.0.3
Search vendor "Emc" for product "Connectrix Manager" and version "12.0.3"
converged_network_edition
Affected