
According to researchers at the security company Rapid7, this vulnerability (of the command injection type) can be exploited by attackers to execute arbitrary operating system commands.
[alert variation=”alert-info”]HP's SiteScope is a solution specially designed for the management and monitoring (monitoring) of performance and availability of IT infrastructures, including servers, network services, devices, applications and operating systems.[/alert]
An advisory announcement published on Friday by Rapid7 reveals that the administration panel of SiteScope could, in many cases, be accessed via <server>:8080/SiteScope/servlet/Main.
Although the control panel should be protected with a password, users are not required to set a password after installing the product, which means that default installations could be exposed to hacking attacks.
Researchers point out that if an attacker manages to gain access to the management console, they can subsequently execute operating system commands via unsanitized input fields of the DNS SiteScope Tool.
The DNS Tool allows users to specify the DNS Server and the host name, but since the fields are not sanitized, an intruder can input any operating system command, instead of the information that should normally be entered.
[signoff icon=”icon-target”]H Rapid7 demonstrated how an intruder can exploit this vulnerability to create a new user and add it to the local administrators group[/signoff]
It is worth noting that remote execution of arbitrary commands is possible only on SiteScope installations running on Windows, as on this operating system the product requires local network access in order to function correctly.
The vulnerability was discovered by researchers Kirk Hayes of Rapid7 and Charles Riggs of Knowledge Consulting Group on June 1st and was initially reported through HP's Zero Day Initiative (ZDI) program.
