Hoşgeldin Misafir

LISTSERV Maestro 9.0-8 Remote Code Execution Vulnerability

Asım Gürsoy

mersin
27 Mar 2020
8,833 Mesaj

Aktiflik

Seviye

Deneyim

TIM / GÖREV:
LISTSERV Maestro 9.0-8 Remote Code Execution Vulnerability--


Kod:
Document Title:
 
===============
 
LISTSERV Maestro Remote Code Execution Vulnerability
 
  
 
References (Source):
 
====================
 
https://www.securifera.com/advisories/sec-2020-0001/
 
https://www.lsoft.com/products/maestro.asp
 
  
 
Release Date:
 
=============
 
2020-10-20
 
  
 
Product & Service Introduction:
 
===============================
 
LISTSERV Maestro is an enterprise email marketing solution and allows you to
easily engage your subscribers with targeted, intelligence-based opt-in
campaigns. It offers easy tracking, reporting and list segmentation in a
complete email marketing and analytics package.
 
  
 
  
 
Vulnerability Information:
 
==============================
 
Class: CWE-917 : Expression Language (EL) Injection
 
Impact: Remote Code Execution
 
Remotely Exploitable: Yes
 
Locally Exploitable: Yes
 
CVE Name: CVE-2010-1870
 
  
 
Vulnerability Description:
 
==============================
 
A unauthenticated remote code execution vulnerability was found in the
LISTSERV Maestro software, version 9.0-8 and prior. This vulnerability stems
from a known issue in struts, CVE-2010-1870, that allows for code execution
via OGNL Injection. This vulnerability has been confirmed to be exploitable
in both the Windows and Linux version of the software and has existed in the
LISTSERV Maestro software since at least version 8.1-5.  As a result, a
specially crafted HTTP request can be constructed that executes code in the
context of the web application. Exploitation of this vulnerability does not
require authentication and can lead to root level privilege on any system
running the LISTServ Maestro services.
 
  
 
Vulnerability Disclosure Timeline:
 
==================================
 
2020-10-12: Contact Vendor and Request Security Contact Info From Support
Team
 
2020-10-12: Report Vulnerability Information to Vendor
 
2020-10-12: Vendor Confirms Submission
 
2020-10-13: Vendor Releases Patch
 
2020-10-13: Securifera Confirms With Vendor that the Patch Mitigates
CVE-2010-1870 but suggest upgrading vulnerable struts library
 
2020-10-15: Vendor Approves Public Disclosure
 
  
 
  
 
Affected Product(s):
 
====================
 
LISTSERV Maestro 9.0-8 and prior
 
  
 
Severity Level:
 
===============
 
High
 
  
 
Proof of Concept (PoC):
 
=======================
 
A proof of concept will not be provided at this time.
 
  
 
Solution - Fix & Patch:
 
=======================
 
Temporary patch:
https://dropbox.lsoft.us/download/LMA9.0-8-patch-2020-10-13.zip
 
#  0day.today [2020-10-24]  #