← Advisories

Secure Computing SnapGear Management Console SG560 v3.1.5 Arbitrary File Read/Write

High
Advisory ID
ZSL-2020-5568
Release Date
04 June 2020
Vendor
Secure Computing Corp. - http://www.securecomputing.com
Affected Version
3.1.5u1
Tested On
fnord/1.9, Apache 1.3.27 (Unix), Linux 2.4.31
Summary

The SG gateway appliance range provides Internet security and privacy of communications for small and medium enterprises, and branch offices. It simply and securely connects your office to the Internet, and with its robust stateful firewall, shields your computers from external threats.

Description

The application allows the currently logged-in user to edit the configuration files in the system using the CGI executable 'edit_config_files' in /cgi-bin/cgix/. The files that are allowed to be modified (read/write/delete) are located in the /etc/config/ directory. An attacker can manipulate the POST request parameters to escape from the restricted environment by using absolute path and start reading, writing and deleting arbitrary files on the system.

Proof of Concept
Disclosure Timeline
N/A
Credits
Vulnerability discovered by Gjoko Krstic
References
Changelog
04.06.2020Initial release
05.06.2020Added reference [1], [2] and [3]
24.03.2026Added reference [4]